Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How does ShipReady Metrics track security testing evidence?

Last verified

ShipReady Metrics organizes pen-test reports, scan results, SAST/DAST findings, remediation, and retests as reviewable, framework-mapped evidence. It does not replace an independent pen test and does not issue a certification. This page is not legal advice.

SRM security-testing evidence, last verified 10 September 2026 against shipped product capability (evidence review, met-verdict overlay, obligation map, controls crosswalk) and against AICPA TSC and ISO/IEC 27001:2022 only where this page maps artifacts to those instruments. Mapping is illustrative. Not legal advice. Not a certification.

Capability walkthrough — organize, do not replace

Audience: a ShipReady Metrics user preparing audit-ready proof. This page is not legal advice. Kind of text: product behavior below is shipped capability, stated without puffery. AICPA TSC and ISO/IEC 27001:2022 are named only as mapping targets — they are not a finding that YOU are in scope. Industry best practice still wants an independent tester. ShipReady Metrics recommendation: use the product as the evidence file, not as the pen test.

Screenshots are not embedded here. The walkthrough is the signed-in path in prose so this public page does not href app routes.

Capability-to-workflow table

Last verified 10 September 2026. Density-honest. Not a certification. Not legal advice.

How shipped capabilities attach to a testing workflow (organizes evidence; does not replace a pen test)
Workflow stepShipped capabilityHonesty caveat
Ingest scanner and CI findingsDependabot, code-scanning, secret-scanning ingest with KEV, EPSS, CVSS, cross-source dedup, and blast radius. First-party SAST and DAST.Ingest is not an independent pen test.
Attach the annual (or change-triggered) reportEvidence collection and review. A reviewer records a met-verdict overlay on the artifact.A met verdict is not a SOC 2 or ISO certificate.
Map to frameworksObligation map plus a controls crosswalk of about 72 canonical controls.Crosswalk density is disclosed. Marking a framework in-scope is not a determination that it applies to YOU.
Share postureShipReady Passport is a shareable posture artifact.A passport is not a pen-test report and is not filed with a regulator. This page does not href the app route.
Retest and remediationVulnerability remediation tracking plus evidence overlay for the confirmation letter.The product does not perform the retest.

What to do now

Operational steps. Last verified 10 September 2026. Not legal advice.

  • Upload authorization, report, tickets, and retest as four artifacts, not one unnamed PDF.
  • Map them to the criteria you actually claimed. Do not invent a “SOC 2 requires annual pen test” control the TSC does not contain.
  • Keep continuous ingest running. Open the continuous-testing and report-contents guides on this site.
  • If you already have a session: signed-in app → Compliance → Evidence. Naming that path is not a public href.

Checklist

Question list. Not a certification. Not legal advice.

  • Is every testing artifact reviewed, not only uploaded?
  • Does the crosswalk show coverage density instead of a fake complete badge?
  • Would an examiner still see an independent tester’s letterhead?
  • Are we describing Passport as posture sharing, not as a filing?

Where this shows up in ShipReady Metrics

Evidence collection, review, met-verdict overlay, obligation map, controls crosswalk (density-honesty), vuln management (KEV, EPSS, CVSS, dedup, blast radius), first-party SAST/DAST, and ShipReady Passport. This product organizes evidence. It does not replace an independent pen test, does not file with anyone, does not determine that a framework applies to YOU, and does not start a clock.

Primary sources (last verified 10 September 2026)

Shipped ShipReady Metrics surfaces listed above (authoritative for capability claims). AICPA Trust Services Criteria and ISO/IEC 27001:2022 for the mapping claims only. Not legal advice.

Frequently asked questions