Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How does ShipReady Metrics track security testing evidence?
Last verifiedShipReady Metrics organizes pen-test reports, scan results, SAST/DAST findings, remediation, and retests as reviewable, framework-mapped evidence. It does not replace an independent pen test and does not issue a certification. This page is not legal advice.
SRM security-testing evidence, last verified 10 September 2026 against shipped product capability (evidence review, met-verdict overlay, obligation map, controls crosswalk) and against AICPA TSC and ISO/IEC 27001:2022 only where this page maps artifacts to those instruments. Mapping is illustrative. Not legal advice. Not a certification.
Capability walkthrough — organize, do not replace
Audience: a ShipReady Metrics user preparing audit-ready proof. This page is not legal advice. Kind of text: product behavior below is shipped capability, stated without puffery. AICPA TSC and ISO/IEC 27001:2022 are named only as mapping targets — they are not a finding that YOU are in scope. Industry best practice still wants an independent tester. ShipReady Metrics recommendation: use the product as the evidence file, not as the pen test.
Screenshots are not embedded here. The walkthrough is the signed-in path in prose so this public page does not href app routes.
Capability-to-workflow table
Last verified 10 September 2026. Density-honest. Not a certification. Not legal advice.
| Workflow step | Shipped capability | Honesty caveat |
|---|---|---|
| Ingest scanner and CI findings | Dependabot, code-scanning, secret-scanning ingest with KEV, EPSS, CVSS, cross-source dedup, and blast radius. First-party SAST and DAST. | Ingest is not an independent pen test. |
| Attach the annual (or change-triggered) report | Evidence collection and review. A reviewer records a met-verdict overlay on the artifact. | A met verdict is not a SOC 2 or ISO certificate. |
| Map to frameworks | Obligation map plus a controls crosswalk of about 72 canonical controls. | Crosswalk density is disclosed. Marking a framework in-scope is not a determination that it applies to YOU. |
| Share posture | ShipReady Passport is a shareable posture artifact. | A passport is not a pen-test report and is not filed with a regulator. This page does not href the app route. |
| Retest and remediation | Vulnerability remediation tracking plus evidence overlay for the confirmation letter. | The product does not perform the retest. |
What to do now
Operational steps. Last verified 10 September 2026. Not legal advice.
- Upload authorization, report, tickets, and retest as four artifacts, not one unnamed PDF.
- Map them to the criteria you actually claimed. Do not invent a “SOC 2 requires annual pen test” control the TSC does not contain.
- Keep continuous ingest running. Open the continuous-testing and report-contents guides on this site.
- If you already have a session: signed-in app → Compliance → Evidence. Naming that path is not a public href.
Checklist
Question list. Not a certification. Not legal advice.
- Is every testing artifact reviewed, not only uploaded?
- Does the crosswalk show coverage density instead of a fake complete badge?
- Would an examiner still see an independent tester’s letterhead?
- Are we describing Passport as posture sharing, not as a filing?
Where this shows up in ShipReady Metrics
Evidence collection, review, met-verdict overlay, obligation map, controls crosswalk (density-honesty), vuln management (KEV, EPSS, CVSS, dedup, blast radius), first-party SAST/DAST, and ShipReady Passport. This product organizes evidence. It does not replace an independent pen test, does not file with anyone, does not determine that a framework applies to YOU, and does not start a clock.
Primary sources (last verified 10 September 2026)
Shipped ShipReady Metrics surfaces listed above (authoritative for capability claims). AICPA Trust Services Criteria and ISO/IEC 27001:2022 for the mapping claims only. Not legal advice.