compliance-coverage-scoring
Compliance coverage scoring
Resolve a named framework to its criteria list, score each criterion against the evidence that actually exists, and record every excluded criterion with the four fields that make an exclusion survivable under challenge.
This produces a readiness self-assessment only
The result is a readiness self-assessment: not certification, not an attestation, not an audit opinion, and not legal advice. Nothing produced here demonstrates compliance to a regulator, a customer, or a court. It is an internal gap list that tells a team what to fix before a qualified party looks, and only a qualified party can attest - none of them is you.
Write that framing into the artifact itself, at the top, every time. A readiness matrix that circulates without it gets mistaken for evidence of compliance. For who can attest per framework and for precise result wording, see references/frameworks.md.