Ratings
A Rating records how well a client currently implements one control, on that control’s own 1–5 maturity scale. Only assessors can record or revise ratings, and only while the engagement is in_progress. The control being rated must also be Active and within the engagement’s scoped pillars.
Recording a rating
| Field | Notes |
|---|---|
| Maturity level | 1–5. Read the control’s own maturity descriptors to pick the right level — each control defines what each level means for itself. |
| Justification | Free text explaining the rating. |
| Relied-upon evidence links | Optionally cite which approved evidence link(s) this rating is based on. |
Justification and sufficient evidence
A rating needs a written justification unless it cites at least one “sufficient” evidence link — meaning an Approved link that is not currently Stale. If you cite evidence links, every one you list must currently qualify as sufficient, or the save is rejected. In short: back up a rating with good evidence, or explain it in writing.
Revising a rating
Ratings can be revised at any time while the engagement is in_progress — there’s no separate approval gate on the rating itself; saving immediately feeds into scoring. Every save (initial or revision) is kept in a full, append-only history, so nothing is overwritten or lost.
Needs revalidation
A rating is flagged needs revalidation — computed live, never stored — whenever a link it relied on has since been rejected, superseded, or gone stale. Watch for this flag on ratings you thought were already settled; it means the evidence backing them has moved since you last touched them.
Next step
Once controls are rated, set Pillar Targets to define what “good” looks like for this engagement, then review the computed Scores and Gaps.