Keep several programs separate
Certification Portfolio lets Professional and MSP organize several audit programs for a client. Each program has its own scope, owners, findings and conclusions.
Understand what the software helps you do—and where your reviewers still make the decision.
Current product family · Version 4.1.0
Certification Portfolio lets Professional and MSP organize several audit programs for a client. Each program has its own scope, owners, findings and conclusions.
Evidence lineage is the connection from a finding or report back to its supporting collection records, timestamps and integrity hashes.
Inspect missing results, conflicting evidence and observed conditions before a conclusion is approved. Technical results are not automatic governance approval.
Record actions against the relevant control, system or finding, then review new evidence after the change.
Use policies, risk records, internal audits and management reviews alongside assessment evidence. MSP governance projection prepares suggestions for a human reviewer.
Use evidence storage, integrity checks, freshness information and applicable retention or legal-hold controls. An integrity hash checks whether content changed; it does not prove the evidence is complete.
Use framework-native requirements and terminology. Evidence can support different programs while conclusions remain separate.
Maintain a timeline, escalation details and linked evidence in the Incident Response workspace available in Professional and MSP.
Export reports and linked evidence for review. Access and report formats depend on the selected edition and version.
Bring the active program’s controls, findings, evidence, risks and governed records into clause review. Suggested status and gaps stay linked to their sources, with human final approval.
Work through the requirements with evidence, owners, sampling and workpapers. Readiness checks use the same records as the full workspace.
Use a KPI strip, status donut, severity and readiness bars, evidence sufficiency and remediation views in Executive HTML. Other exports share the data; DOCX/PDF currently use metric and text-bar summaries.
Historical multi-run trends and richer graphical DOCX/PDF output remain separate roadmap work. Professional and Free have their own release scope.
Framework pages distinguish exact technical mappings, broader supporting scope and evidence needing manual review.
Frameworks & controlsFind plain-language definitions of Certification Portfolio, evidence lineage, Installation ID and other product terms.
Product glossary