How it works
How the assessment actually runs.
This page is the assessment step by step, from scope to finished report. If you want to know what it produces and what it costs, see what you get.
Audit41 Readiness follows the path a working auditor takes. It is not a questionnaire that scores your own opinion of yourself. It builds the same three lines of evidence an auditor builds a judgment from, and it tells you where they disagree.
The method
An auditor does not take your word for it.
An audit rests on three legs. What your policies say you do, what your evidence shows you actually did, and what the people running the systems say when you ask them. An auditor forms a judgment where those three agree, and finds the gaps where they do not. The assessment works the same way.
Policies. What you say you do.
Your documented position. Policies, procedures, standards, the rules you have written down. This is the claim.
Evidence. What you can show.
Logs, configurations, records, tickets, reports, screenshots. This is what stands behind the claim.
Interview. What the people running it say.
The distance between a written policy and daily practice shows up in conversation, not in a document.
Where the three agree, you are covered, and the report says so. Where they diverge, that is a gap, and the report says where it is and why it matters.
Step by step
Five steps, start to finish.
Scope
You tell us where your organization is established and what it does. The assessment applies your country's transposition of NIS2, or the framework you selected. You are assessed against the rules that apply to you, not a generic European baseline.
Systems and policies
Register the systems in scope and submit your documented position. Policies, procedures, standards, the rules you have written down. This is what you say you do.
Evidence
Submit what stands behind the claim. An access control list, a backup log, a firewall configuration, an incident ticket, a training record, a screenshot of a setting. PDFs, Word documents, spreadsheets, exports from other tools, images, whatever format you already hold it in. Nothing to reformat and no template to fill in first.
The interview
Sage asks how each requirement works in practice, the way an auditor would, and explains what a requirement is actually asking for when the wording is not obvious. Frameworks are written for auditors, not for the people being audited. Sage identifies itself as AI in its first message.
Evaluation
Every requirement group is evaluated against what you actually produced across all three. Each finding is tied back to the policy, the evidence, or the answer it came from, so you can see why it landed where it did.
The output
What you have at the end.
A scored position against the framework you selected, across every requirement group.
Every gap, ranked by severity, tied to the control it fails.
An action plan in priority order, ranked by risk exposure and the effort to close.
A one-page summary for the people who need the position without the detail.
It does not certify you and it does not replace the audit your regulator or your certification body requires. It gives you the same picture they will build, earlier, while there is still time to act on it.
The rerun
Close the gaps, then prove it.
The assessment is not a one-time snapshot. Every plan includes one full rerun. Work through the action plan, then run the whole assessment again and see what moved: your new score against your old one, gap by gap, control by control. Additional reruns can be purchased if you want to track progress more often.
First run
48/100
After rerun
82/100
A score on its own is a number. A score that moved is evidence the work landed, for your board, for your auditor, and for you.
Sage
One advisor, from the first question to the last fix.
Sage stays with you across both halves of the work.
During the assessment
Sage explains what a requirement is asking for at the point where you are answering it, in the context of what you have already submitted. You are not left guessing what a control means before you can answer honestly.
After the assessment
Sage reads your finished report, tells you which gaps to close first and why, and drafts the policy text that closes them. Ask it about a specific finding and it answers against your results, not in general.
Available on Professional and Programme. Sage identifies itself as AI in its first message.
Start where you are.
The free self-check takes a few minutes. It applies your country's rules, tells you whether you are in scope and as what, and recommends the assessment that fits.
Start the free self-check→