Establish the assessment context
Connect to the intended MSP server before creating records. Create or select the client, then select its Certification Portfolio program and framework. Name the program for the real scope and audit period; different scopes or certification instances belong in separate programs. Verify that the active client and program are visible before entering evidence or starting a run.
Configure scope and ownership
Record the organization, domain or tenant, owner, included assets and explicit exclusions. Limit discovery to approved subnets and targets. Do not infer authorization from network reachability. For a multi-program client, check that the selected program owns the run and evidence you are about to create.
Configure only needed collectors
Use Settings & Credentials and Dependencies to configure the modules actually in scope. Directory and Group Policy collection require authorized directory access. Windows collection requires its supported remote management path; Linux targets require their configured secure access. Cloud collection needs the approved tenant and requested permissions. Network, VMware, storage and backup connectors need their own management endpoints and access rights.
TLS targets can come from configured assessment subnets and optional manual host/port or HTTPS entries. Review the discovered targets, exclusions and deduplication. Vulnerability CSV ingestion uses an authorized export; it does not run a vendor's scanner or establish complete vulnerability coverage by itself.
Save, test and confirm
Save each configuration change, then run the matching dependency/connection check. A successful save is not a successful network test. Resolve the failed stage shown by the app. Use the framework coverage pages to distinguish enabled collectors from explicit control-to-test mappings. Broad family applicability never guarantees a mapped result for every requirement.
Pilot and review
Run a small known-scope assessment. Watch the target/module progress and command evidence where available. Review not-run, unsupported, access-denied and no-data outcomes separately from test failures. Verify one or more raw evidence records for each enabled module, then inspect the framework-specific workpapers and reports. Assign an owner to unresolved findings and evidence gaps before expanding the scope.
Guide basis
Master operations guide; R68 packaged Configuration, Network, Backup and Audit Modules guides
Published as a website guide on 1 October 2026. Where a bundled reference is older, the version-specific guide and installed interface take precedence.