AI-native assessment platform
AssessIQ
The assessment execution platform for FedRAMP, FISMA, DoD SRG, NIST SP 800-171 and FedRAMP 20x engagements. Built by assessors, for the assessment firm.
What it is
The assessor keeps the judgment. The platform removes the reading.
AssessIQ reads a system’s evidence corpus, drafts every Examine, Interview and Test write-up in plain assessor language, flags discrepancies across sources, and runs adversarial quality control before the assessor signs.
What it does not do is conclude. Every determination stays with the assessor, procedure by procedure. Assessor edits are locked, so refreshed draft text lands beside your words rather than over them. What comes out of the schedule is the reading, matching and drafting time, which is where the hours actually go.
We built it because we run assessments ourselves. It is in production on live engagements now.
- 30%FedRAMP Low
- 35%FedRAMP Moderate
- 40%FedRAMP High
- 42%High with a large SSP corpus
Estimated assessor-labor savings against a conventional assessment of the same scope. The advantage grows with the size of the evidence corpus. Assessor review time is unchanged by design.
What it does
Three jobs, run in order, on every engagement.
Reads the evidence
- SSPs, policies, procedures, transcripts, artifacts and screenshots
- Documents auto-classified by type and scope
- Per-control evidence pulled from hundreds of pages, with no manual highlight-and-quote
Drafts the assessment
- Examine, Interview and Test write-ups per procedure, determination first
- Plain assessor language, one house style
- Evidence requests and interview questions tailored to the corpus
Catches errors before delivery
- Dual-pass adversarial QC on every write-up
- Discrepancy findings across SSP, interview and test sources
- Delivery Manager sampling and a tamper-evident audit trail
At a glance
What runs on the platform today.
- FedRAMP (NIST 800-53 Rev 5)
- NIST 800-53 Rev 5 and FISMA
- NIST SP 800-171 (130 requirements)
- DoD Cloud SRG (IL4, IL5, IL6)
- NIST 800-172 and CSF 2.0
- FedRAMP 20x (Key Security Indicators)
- SAR and SAP (Word)
- SRTM, POA&M, RET (Excel)
- SPRS score sheets
- Evidence request list and interview bank
- KSI OSCAL, KSI summary, 20x package
- Raw assessment workbook
- Four roles with 19 granular permissions
- Super Admin, Admin, Delivery Manager, Assessor
- Company-scoped tenant isolation
- MFA, passkeys and SSO through Entra ID, Okta or Google Workspace
Time recovered
One assessor, one month: 120 of 160 hours back.
Modelled on a NIST 800-53 Rev 5 Moderate baseline of 175 procedures in a 160-hour month, at a five-minute blended review per procedure. The assessor reads each drafted write-up against its cited evidence, then signs or adjusts.
A planning model, stated so it can be checked. It is not a time study. Tool processing runs unattended and is not assessor time.
Stage by stage
Where the 120 hours come from.
| Stage | The work | Conventional | With AssessIQ | Saved |
|---|---|---|---|---|
| Read the package | Tool reads, classifies and maps the corpus; assessor reads per-control summaries | 31 h | 8 h | 23 h |
| Map the evidence | Tool matches artifacts to procedures; assessor spot checks | 23 h | 2 h | 21 h |
| Work the interviews | Tool works transcripts and notes; assessor confirms attribution | 16 h | 4 h | 12 h |
| Write the results | Tool drafts all 175 write-ups; assessor reviews and signs each | 58 h | 15 h | 43 h |
| Chase inconsistencies | Tool flags cross-source conflicts; assessor adjudicates | 8 h | 3 h | 5 h |
| QC the work | Tool runs dual-pass quality check; assessor rules on flags | 12 h | 4 h | 8 h |
| Assemble deliverables | Tool builds SAR, risk table and requirements matrix; assessor reviews | 12 h | 4 h | 8 h |
| The 160-hour month | 160 h | 40 h | 120 h |
Hours are assessor hours. Engagement cadence (standups, briefs, coordination) rides outside both columns. The firm’s independent quality review under its own accreditation sits on top of both and is neither compressed nor counted.
Delivery calendar
A Moderate analysis phase inside 14 business days.
Agencies emulating FedRAMP 20x expect assessment calendars measured in days and weeks, not months. This is a document-based Rev 5 analysis phase meeting that expectation. The ambition is calendar speed rather than feature parity.
Three assessors on dedicated assignment, about 89% loaded. At a ten-minute review the window runs about 17 days. The same dedicated team conventionally needs about 50 business days.
Scale
The saved share holds at every baseline.
Three quarters recovered at every baseline, so deeper reviews save more hours in absolute terms.
Measured, not modelled
Document analysis times from a live engagement corpus.
Wall-clock times from intake to control-mapped output, recorded by the platform. None of it is assessor time. Processing starts on upload and runs unattended inside the tenant’s selected AI data path.
| Document | Pages | Tool time | Output |
|---|---|---|---|
| System access review export | 1,819 | 2.7 min | 125 control-mapped evidence pulls |
| Vulnerability scan evidence export | 5,830 | 0.6 min | Indexed to the scan evidence workflow |
| Continuous monitoring workbook | 138 | 2.8 min | 26 control-mapped evidence pulls |
| Security program policy | 21 | 4.3 min | 47 control-mapped evidence pulls |
| Asset inventory record | 1 | 0.9 min | 3 control-mapped evidence pulls |
| One measured delivery | 7,809 | 11.3 min | Read, classified and processed, unattended |
Framework coverage
One workflow across every framework you run.
| Framework | Catalog | Scope tiers | Deliverables |
|---|---|---|---|
| FedRAMP (NIST 800-53 Rev 5) | 2,176 procedures | Low / Moderate / High | SAR, SAP, SRTM, POA&M, RET, raw |
| NIST 800-53 Rev 5 (non-FedRAMP) | 2,761 native procedures | Low / Moderate / High | SAR, SRTM, POA&M, raw |
| FISMA | Native NIST catalog | Low / Moderate / High | SAR, SRTM, POA&M, raw |
| DoD Cloud Computing SRG | 800-53 master + 10 GRRs | IL4 Mod / IL4 High / IL5 / IL6 | SAR, SRTM, POA&M, RET, raw |
| NIST SP 800-171 Rev 3 | 130 requirements | FCI / CUI / CUI Enhanced | Assessment report, SPRS, POA&M, raw |
| NIST SP 800-172 | Enhanced requirements | Enhanced | Assessment report, POA&M, raw |
| NIST CSF 2.0 | 185 outcomes | All functions | Assessment report, raw |
| FedRAMP 20x (Key Security Indicators) | FRMR-synced KSIs | KSI | KSI OSCAL, KSI summary, 20x package |
Security and trust
Your content stays inside the data path you choose.
You select an authorized AI data path per tenant and per engagement. Content stays inside it on every call, and bring-your-own-model credentials are supported.
| Data path | Model families | Use |
|---|---|---|
| Google Vertex AI | Claude, Gemini | Sovereign lane; Assured Workloads for regulated engagements |
| AWS Bedrock | Claude | Sovereign lane; GovCloud available |
| Azure AI Foundry | GPT-5 family | Boundary lane for FedRAMP High and DoD IL2 tenants |
- Tenant isolation enforced on every query, with roles and granular permissions
- MFA, passkeys and SSO through Entra ID, Okta or Google Workspace
- Tamper-evident audit trail, encrypted secrets and a web application firewall
- Per-tenant AI spend guardrails with alert and hard-stop thresholds, and a guardrail pause never changes an assessment result
- Continuous security scanning of the platform, mapped to NIST 800-53 controls
- Runs in Azure Commercial East, a FedRAMP High platform-authorized region
The line we do not cross
What stays with the assessor.
- Every determination, signed procedure by procedure
- Interview conduct and professional judgment
- Sampling depth and evidence sufficiency calls
- Final wording, with assessor edits locked rather than overwritten
- Where the dual-pass QC disagrees with itself, the question defers to a human
Tell us what the contract requires. We’ll tell you what it takes.
A 30-minute scoping call is usually enough to size the gap, name the deliverables and give you a realistic date for authorization.
