The report is the face of an assessment: whatever isn't cleanly in the report effectively doesn't exist for the auditor, management, or the measure owner. SecTepe.Core has therefore reworked the compliance assessment report from the ground up – with a complete gap analysis, a structured action plan, and exports that finally all speak the same language.
Every Requirement in the Gap Analysis – Not Just the Gaps
Previously the gap analysis mainly showed the conspicuous deviations. The new PDF report lists every requirement in the gap section – fulfilled, partially fulfilled, or open. This yields a complete picture and answers the auditor's question "and what about requirement X?" without a lookup.
Action Plan by Type
The report is complemented by an action plan organized by measure type. The identified gaps thus become directly traceable, grouped work packages – the bridge from "something is missing here" to "this needs to be done".
A More Honest Management Summary
The management summary became noticeably more precise:
- Partially fulfilled answers are credited and enter the assessment proportionally – instead of a binary "fulfilled/not fulfilled".
- Recorded nonconformities count as open gaps, so the summary shows the actual need for action.
- Gap analysis and action plan are merged, so finding and response no longer drift apart into separate chapters.
All Exports on One Structure
Perhaps the most practical part: the exports to CSV, XML, PowerPoint, Word, and Excel were all rebuilt along the section structure of the PDF report. Where you previously got slightly different content depending on the format, you now have the same structure in every format – whether for the board presentation (PPTX), further processing (CSV/XML), or the working document (Word/Excel).
Which Frameworks This Applies To
The compliance assessments in SecTepe.Core cover, among others, NIS2, GDPR, ISO/IEC 27001:2022, BSI IT-Grundschutz, DIN SPEC, SOC 2 Type II, HIPAA, and PCI DSS. The new report applies across frameworks – a uniform report for a multi-framework ISMS. How standard updates can be tracked automatically across them is shown in the post on framework change management.
Conclusion
The reworked assessment report turns an evaluation result into an audit-ready, action-guiding document: complete gap analysis, action plan by type, an honest summary, and exports consistent across all formats. That is exactly what reduces audit preparation from months to weeks.