AssurSight Continuous Assurance

Continuous assurance from live service evidence.

Connect operational service data to cyber-resilience outcomes so providers and customers can see what is working, what is evidenced, where gaps remain and what action is required.

  • Provider and customer assurance profiles
  • Evidence linked to live service data
  • NIST and CAF readiness views
  • Owned actions with human approval
Continuous AssuranceNorthwind Logistics
Evidence current
Evidenced42Current observations
Partial8Gaps remain
Stale5Refresh required
Open actions11Owned and tracked
PR
Protective technologyMicrosoft Defender configuration observed 2 hours ago
Evidenced
RC
Recovery planningRestore test is 94 days old and due for refresh
Partial
GV
Shared responsibilityCustomer confirmation required for privileged-access review
Awaiting
Current profileEvidenceOwned actionTarget profile
2 scopesProvider operations and managed customer 1 evidence engineReuse observations across frameworks 6 clear statesNo opaque compliance percentage Human governedAI assists; providers approve
An assurance layer—not another GRC platform

Keep assurance connected to the service being delivered.

AssurSight already brings together services, devices, integrations, documents, workflows and reporting. Continuous Assurance connects that same delivery record to recognised cyber-resilience outcomes.

Instead of completing a questionnaire that becomes stale immediately, providers can show which service contributes to an outcome, who owns it, what current evidence supports it and what should happen next.

See the platform foundation
01
Service contributionShow exactly what each contracted service supports.
02
Current evidenceLink telemetry, devices, documents, reports and workflow history.
03
Clear ownershipAssign provider, customer, shared or vendor responsibility.
04
Operational actionTurn a gap into a task, recommendation, assignment or PSA ticket.

One assurance engine. Two distinct scopes.

Separate the provider’s own resilience from the security outcomes supported through managed customer services.

Scope 01

Provider Operations

The critical systems, suppliers, people and processes the MSP or MSSP relies on to deliver managed services.

  • Management, PSA and service platforms
  • Identity and privileged-access systems
  • Backup, recovery and continuity arrangements
  • Critical suppliers and subcontractors
  • Incident response and customer notification
Where the provider’s own resilience and Bill readiness sit.
Scope 02

Managed Customer

The cyber-resilience outcomes supported by the services delivered to each managed customer.

  • Current and Target Profiles
  • Contracted services and product packs
  • In-scope devices and environments
  • Customer, provider and vendor responsibilities
  • Evidence, exceptions and improvement plans
Where customer-visible assurance and service improvement sit.

Connect services to outcomes—and outcomes to evidence.

A common outcome-and-evidence engine lets one current observation support several framework views without duplicating the underlying evidence.

  1. 1Define the outcome

    Select the cyber-resilience outcome that should be achieved.

  2. 2Map the service

    Show which catalogue service, pack or process contributes.

  3. 3Assign responsibility

    Record provider, customer, shared or vendor ownership.

  4. 4Attach evidence

    Link integrations, devices, documents, tickets and reports.

  5. 5Assess freshness

    Record what the evidence proves and how current it remains.

  6. 6Create the action

    Turn the gap into owned work and track it to closure.

Reusable evidence observation

Microsoft Defender policy assessment

One dated configuration observation can support mapped outcomes across NIST CSF, CAF, Cyber Essentials and ISO without copying the evidence into four separate assessments.

Source
Microsoft Defender integration
Observed
29 July 2026, 09:42
Freshness
Current
Responsible party
Provider
Transparent assessment states

Explain the position instead of hiding it behind a percentage.

Every result should show its source, observation date, freshness, scope and responsible party.

AssurSight can still provide summary views, but the underlying evidence state remains visible and traceable.

Evidenced

Current evidence supports the outcome.

Partially evidenced

Some requirements are supported, but material gaps remain.

Awaiting confirmation

Evidence or confirmation is still required.

Exception accepted

The gap has been reviewed and formally accepted.

Not addressed

No adequate evidence or accepted treatment exists.

Not applicable

The outcome does not apply to the defined scope.

One engine with versioned framework packs.

Use the same service mappings, responsibilities and evidence observations through different readiness and assurance views.

NIST

NIST CSF 2.0

Create Current and Target Profiles, identify gaps and prioritise outcomes across Govern, Identify, Protect, Detect, Respond and Recover.

Official NIST Profiles guidance ↗
CAF

NCSC CAF 4.0 Basic Profile

Assess UK-focused cyber-resilience outcomes and show evidence against the CAF Basic Profile target level.

Official NCSC CAF collection ↗
UK

Cyber Security and Resilience Bill readiness

Organise provider evidence around proposed MSP duties, supplier resilience and incident-reporting readiness.

Official Bill stages ↗
MAP

Existing framework mappings

Reuse evidence through Cyber Essentials, ISO 27001, IASME and provider-defined assurance profiles.

Use “aligned”, “mapped” and “readiness”—not certification claims.

AssurSight supports alignment, readiness and evidence management. It does not certify an organisation or guarantee legal compliance.

UK cyber-resilience readiness

Prepare for changing obligations without making unsupported compliance claims.

The Cyber Security and Resilience (Network and Information Systems) Bill is progressing through Parliament and is not yet law. Detailed thresholds and technical requirements will continue to develop through consultation, secondary legislation and regulator guidance.

AssurSight should support structured readiness, evidence and governed incident preparation. It should not determine legal applicability or guarantee compliance.

Regulatory context reviewed 29 July 2026. This content is product information, not legal advice.
Regulatory incident modeHuman-approved readiness workflow
00:00
Assess reportabilityCapture service, scope, known impact and evidence.
24h
Initial notificationPrepare the light-touch regulator and NCSC notification.
72h
Full reportDraft the fuller report using the known evidence timeline.
Next
Identify affected customersPrepare customer-impact analysis and approved communications.
Evidence timelineAffected servicesCustomer identificationNotification draftsApproval historyExercise records

Continuous Assurance capabilities that strengthen the core platform.

Each capability reuses the customer, service, evidence, action and reporting records AssurSight already manages.

01

Provider assurance profile

Cover the provider’s own critical systems, suppliers, services, risks and evidence.

02

Customer assurance profile

Maintain Current and Target Profiles for each managed customer.

03

Service-to-outcome mapping

Show exactly what each catalogue service or product pack contributes.

04

Continuous evidence index

Link telemetry, devices, documents, reports, tickets and workflow history.

05

Shared responsibility

Record provider, customer, shared and vendor responsibilities for every outcome.

06

Gap-to-action workflow

Create an owned action, recommendation, service assignment or PSA ticket.

07

Supplier dependency view

Record critical vendors, alternatives, recovery objectives and continuity arrangements.

08

Assurance reporting

Present evidence, gaps and progress in portals, QBR packs and portfolio views.

AI assurance assistant

Evidence-backed assistance, with people in control.

Extend AssurSight AI CSM across assurance workflows without allowing AI to declare compliance or send material notifications on its own.

  • Explain gaps in provider and customer language with citations to supporting evidence.
  • Identify stale evidence and drift before the recorded conclusion becomes misleading.
  • Recommend action based on the current gap, service scope and responsibility.
  • Draft narratives for QBRs, executive reports and readiness updates.
  • Surface opportunities where adoption or service gaps affect the Target Profile.
Explore AI CSM
Assurance assistantWhy is Recovery Planning only partially evidenced?
Evidence-backed answer

The latest backup-status observation is current, but the linked restore exercise was completed 94 days ago and exceeds the provider’s 90-day evidence-freshness policy.

1 Backup integration: healthy, observed 2 hours ago
2 Restore exercise: passed, observed 94 days ago
3 Provider policy: restore evidence valid for 90 days

Boundaries that protect the AssurSight proposition.

Continuous Assurance strengthens service delivery by connecting evidence and action. It does not replace the specialist systems or authorities around it.

Not a certification body

AssurSight supports readiness and evidence; it does not issue external certifications.

Not a full ERM platform

Keep the focus on cyber-resilience outcomes connected to managed services.

Not a SIEM or PSA replacement

Specialist systems remain the source of telemetry, incidents and operational records.

Not definitive legal advice

Applicability and regulatory conclusions remain with the provider and its advisers.

Not automatic regulator submission

Prepare drafts and evidence until final interfaces and provider controls are known.

Not autonomous compliance declaration

AI can assist, but material conclusions and communications require human approval.

Make resilience visible

Turn live service delivery into current assurance evidence.

See how AssurSight can help your provider team connect service scope, evidence, responsibility and action across provider operations and managed customers.