Evidence-First Assessment Standard

EFAS™ Version 1.0 | Published 2026 | Securitique™

EFAS is the only published methodology standard that defines exactly how a rigorous cybersecurity assessment is conducted, the evidence required, the rating standards, the finding elements, and the conduct standards that govern every engagement.

The Founding Principle

"An assessment that cannot be defended is not an assessment. It is an opinion."

EFAS™ Version 1.0 Foreword | Securitique 2026

What EFAS™ Defines

Evidence Standards Three evidence types required. Corroboration requirements for positive ratings. Currency standards with documented exception basis. Evidence rejection standards.

Rating Scales NIST SP 800-53 three-point scale. ISO 27001 five-point conformance scale. CMMC 2.0 three-point scale. Qualified rating standards. Rating consistency requirements.

Finding Standards Ten required elements for every finding. Severity classification standards. Factual correction versus preference-driven revision. Assessor independence requirements.

The Five Principles of EFAS™

Evidence Over Assertion No control is rated, and no finding is documented, based on the client's assertion alone. Every rating requires objective evidence.

Defensibility Over Speed An assessment that is delivered quickly but cannot be defended is worthless. An assessment that takes longer but holds up under scrutiny is valuable.

Independence Over Accommodation Ratings stand on evidence. Client preference does not change a finding. New evidence does.

Specificity Over Generality Every finding names the specific gap, the specific system or process affected, and the specific evidence that supports it.

Improvement Over Compliance The goal of every assessment is a measurable improvement in security posture, not the production of a document that satisfies a checkbox.

Ready to Read the Standard?

EFAS™ Version 1.0 is publicly available. Read it, cite it, and hold us accountable to it. That is the point.