It is not a certification, and it is not proof of compliance. No assessment can
honestly tell you that you are compliant with a framework. Compliance determinations are made by
qualified assessors against a defined scope. A strong readiness result does not make you compliant,
and the Method will never imply otherwise.
It is not a penetration test or a vulnerability scan. Nothing is installed and
nothing touches your systems. Those are valuable and different exercises, and a strong readiness
result is not a substitute for either.
It is not a legal opinion or an insurance coverage determination. It can make your
conversation with a broker or underwriter far more specific and evidence-backed. It cannot tell you
what a carrier will decide.
It is not a guarantee. No assessment can promise an outcome. A business that does
everything the Method recommends can still be attacked successfully. What changes is how likely you
are to detect it, contain it, and recover.
It cannot verify what you cannot evidence. Where no evidence exists, the Method
reports the finding as unverified rather than assuming the best.