Glossary

The terms we use, defined precisely

Readiness is not certification. Coverage is not sufficiency. Evidence status is not assessed readiness. Precise language is how the product stays honest — here is what each term means.

Readiness
An assessed judgement of how well prepared you are for an external assessment or audit against a defined scope. Not certification, compliance, a guarantee, or a real-time state.
Coverage
How much of the applicable requirement set has evidence and/or has been assessed — a completeness measure, distinct from the readiness outcome. Not the same as sufficiency.
Sufficiency
Whether the evidence actually supports a requirement. Coverage answers how much; sufficiency answers whether it holds up. A pile of present files is not the same as sufficient evidence.
Evidence status / hygiene
The lightweight operational signal: is evidence present, approved, current, stale, or missing? An operational view — not an assessment of whether evidence supports a requirement.
Evidence assessed
Evidence whose content has been evaluated against a requirement — distinct from merely collected, approved, or in-date.
Determination
The per-requirement content verdict: sufficient / partial / insufficient / invalid / unable-to-verify / not-assessed. Distinct from a Green/Amber/Red metadata status.
Readiness outcome
The primary result: ready / partially-ready / not-ready / unable-to-determine / assessment-incomplete — set by blocker precedence, not by a percentage.
Blocker
A negative determination (invalid / insufficient) or unable-to-verify that forces a non-ready outcome regardless of percentage.
Blocker register
The artefact listing the requirements that currently prevent a Ready outcome, with reason, traceability, severity, and a remediation overlay — which never resolves a blocker; only reassessment does.
Citation
A finding's link to a specific evidence excerpt (page / section / char-offset / quote-hash), verified verbatim against stored text.
Review level (R0–R3)
The provenance axis: R0/R1 system/AI, R2 customer self-attestation, R3 authorised assessor review. Separate from the determination.
Self-attested (R2)
The customer signs off their own readiness — deliberately not an independent review.
Reviewed / assessor-approved (R3)
An authorised assessor has reviewed and finalised, under competence, conflict-of-interest and separation-of-duties controls. Requires genuine independence before it can be called independent.
Independent
Reviewed (R3) plus a passed engagement independence gate — offered per engagement only, never a blanket platform claim, and never generalised to “all our assessments are independent.”
Tamper-evident
Changes are cryptographically detectable — applies only to the assessment lifecycle ledger (hash-chained), not the general audit log.
Append-only
UPDATE/DELETE revoked; records are added, not changed. Weaker than tamper-evident. We avoid “immutable” entirely.
Continuous Readiness
The platform maintains the currency of assessed readiness as tracked evidence expires, is withdrawn, superseded or invalidated — not continuous monitoring, real-time compliance, or control telemetry.
Assurance
Netallion's evidence-and-readiness support activity — not accredited certification or a warranty of compliance.

Words we never use

These claims overstate what evidence and readiness can support, so we do not write them — about a customer or about ourselves — even informally.

  • “Certified” / “compliant” (of the customer)
  • “Immutable”
  • “Continuous” / “real-time” monitoring
  • “Guaranteed” compliance or certification
  • “Independently verified” for a self- or reviewed outcome
  • “AI-certified” / “AI-verified”

Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. Where the boundary sits.

See the language in practice

The evidence-quality guide shows coverage vs sufficiency at work; the framework guides and a sample export apply the terminology end to end.