Evidence-First Assessment Standard (EFAS™)

Version 1.0 | Published 2026 | Securitique™

EFAS™ is a formal, versioned, publicly citable methodology document that establishes the evidence standards, rating standards, finding standards, deliverable standards, and assessor conduct standards that govern all Securitique™ assessment engagements. It is published openly because any methodology worth following should be able to withstand public scrutiny.

Foreword

"An assessment that cannot be defended is not an assessment. It is an opinion."

EFAS™ Version 1.0 Foreword | Securitique™ 2026

The cybersecurity assessment profession has no shared standard for what constitutes a rigorous assessment. Evidence standards are informal. Rating criteria are undocumented. Findings vary in quality from assessor to assessor and engagement to engagement. The result is a market full of assessments that satisfy compliance requirements on paper while leaving organizations no more secure than before.

EFAS™ was published to change that. It defines precisely and publicly what evidence is required, how controls are rated, what every finding must contain, how deliverables are structured, and how assessors must conduct themselves. It is not a checklist. It is a methodology standard, versioned and citable, that any organization can reference and any assessor can be held accountable to.

Every Securitique™ engagement is governed by EFAS™.

‍ ‍No exceptions.

Section 1

Scope and Application

EFAS™ Version 1.0 applies to all cybersecurity assessment engagements conducted by Securitique™. It governs assessments performed against the following frameworks.

NIST SP 800-53 Rev. 5

Federal information systems, ATO readiness, FISMA compliance, and FedRAMP authorization.

ISO 27001 and 27002

Information security management system assessments and certification preparation.

CMMC 2.0 ‍ ‍

Defense contractor assessments against NIST SP 800-171 Rev. 2 practices across 14 domains.

NIST AI RMF and ISO 42001 AI governance assessments for organizations deploying artificial intelligence systems.

EFAS™ applies without modification to all four frameworks. Framework-specific rating scales and additional requirements are defined in the applicable framework extension sections of this standard.

Section 2

The Five Principles of EFAS™

The following five principles govern every Securitique™ assessment engagement. They are not aspirational statements. They are operational commitments with direct implications for how assessors conduct their work.

Evidence Over Assertion No control is rated, and no finding is documented, based on the client's assertion alone. Every rating requires objective evidence documentation, interview corroboration, or direct technical observation. An assertion without supporting evidence is treated as an evidence gap, not as a basis for a positive rating.

Defensibility Over Speed An assessment that is delivered quickly but cannot be defended under scrutiny is worthless. An assessment that takes longer but produces defensible findings, traceable evidence, and accurate ratings is valuable. Timeline pressure does not change what the evidence requires.

Specificity Over Generality Every finding names the specific gap, the specific system or process affected, the specific evidence that supports the finding, and the specific corrective action required. General observations without specific evidence are not findings under EFAS™.

Independence Over Accommodation Ratings stand on evidence. Client preference does not change a finding. Disagreement with a finding is addressed through the provision of new evidence not through negotiation. An assessor who changes a rating without new evidence has violated EFAS™.

Improvement Over Compliance The goal of every assessment is a measurable improvement in security posture — not the production of a document that satisfies a checkbox. Findings are written to drive remediation, not to document compliance.

Section 3

Evidence Standards

Every control rating and every finding produced under EFAS™ must be supported by objective evidence. The following standards govern how evidence is gathered, evaluated, and documented in every Securitique™ assessment engagement.

The Three Evidence Types

Documentation Review

Policies, procedures, standards, system security plans, configuration records, audit logs, training records, and any other written artifact that demonstrates a control is in place. Documentation alone is not sufficient to support a Met or Implemented rating without corroboration from a second evidence type.

Corroboration Requirement

Structured Interviews

Formal interviews with named personnel conducted using EFAS™ interview guides. Interview responses must be documented with the name, title, and date of the interview. Interview responses alone are not sufficient to support a Met or Implemented rating without corroboration from a second evidence type.

Technical Observation

Direct observation of system configurations, access controls, audit settings, or other technical implementations. Technical observation may be performed in person or via secure remote session. Where technical observation is not possible, the absence must be documented and the rating adjusted accordingly.

A positive rating — Met, Implemented, or Conforming requires corroborating evidence from at least two of the three evidence types. A single evidence type, regardless of quality, is not sufficient for a positive rating under EFAS™. This requirement may not be waived.

Section 4

Rating Standards

EFAS™ defines three rating scales — one for each primary framework. All three scales share the same underlying logic: ratings are assigned based on evidence, not on intent, assertion, or partial implementation without documented basis.

NIST SP 800-53 Rating Scale

Implemented

The control is fully in place, consistently applied, and independently verifiable across the entire system boundary. Corroborating evidence from at least two evidence types is required.

ISO 27001 Conformance Scale

0 — Not Implemented

No evidence of implementation.

CMMC 2.0 Rating Scale

Met

The practice is fully implemented and independently verifiable. No material gaps identified.

AI Governance Rating Scale

Developing

The organization has acknowledged the AI governance requirement but has no documented process, assigned ownership, or verifiable implementation. Awareness exists but governance does not.

Partially Implemented

The control exists but is not fully in place, not consistently applied, or not verifiable across the entire system boundary. Specific gaps must be documented.

1 — Initial

Ad hoc implementation with no documented process.

2 — Developing

Partial implementation with documented intent but inconsistent application.

Partially Met

The practice exists but is not fully implemented across the entire system boundary.

Managed

The organization has documented AI governance processes, assigned ownership, and can demonstrate partial implementation across the AI RMF functions Govern, Map, Measure, and Manage. Implementation is inconsistent or incomplete across all applicable AI systems.

Not Implemented

The control is absent, undocumented, or there is no objective evidence of implementation despite client assertions. Absence of evidence after reasonable follow-up is treated as Not Implemented.

3 — Defined

Documented and consistently implemented across the scope.

4 — Managed

Implemented, monitored, and subject to continual improvement.

Not Met

The practice is absent or there is no objective evidence of implementation.

Defined

The organization has fully implemented, consistently applied, and independently verifiable AI governance processes across all applicable AI systems. Documentation, ownership, monitoring, and continual improvement mechanisms are all in place.

Section 5

Finding Standards

Every finding produced under EFAS™ must contain all ten required elements. A finding that is missing any element is incomplete and must be corrected before the assessment report is delivered. There are no exceptions.

The Ten Required Finding Elements

Finding ID

A unique identifier for tracking and reference across all deliverables.

Finding Title

A concise descriptive title of the gap identified.

Gap Description

A specific description of what is absent, deficient, or inconsistent.

Risk Impact Statement

The specific risk to the organization if the finding is not remediated.

Recommended Owner

The named role or individual responsible for remediation.

Control or Practice Reference

The specific control ID or practice number the finding is associated with.

Severity Rating

Critical, High, Moderate, or Low with documented rationale.

Evidence Reference

The specific evidence items that support the finding.

Corrective Action

A specific, actionable remediation step that addresses the root cause.

Target Completion Date

A recommended timeframe for remediation based on severity.

Section 6

Deliverable Standards

Every Securitique™ assessment engagement produces a standard set of deliverables. The following deliverables are required for every engagement. Additional deliverables may be added based on framework-specific requirements or client agreement.

Executive Summary

A plain-language summary of overall security posture, top findings, risk prioritization, and recommended path forward. Written for senior leadership and authorizing officials. Must include an overall readiness determination.

Control Results Matrix

A complete table showing the assessment result for every control or practice in scope. Every rating must reference the evidence that supports it. No rating without a documented basis.

Evidence Gaps List

A documented list of every evidence item requested but not received. Evidence gaps are distinct from findings they represent missing information that may affect the accuracy of ratings.

Findings Register and POA&M

A complete register of all findings meeting the ten required EFAS™ elements. Where applicable, a Plan of Action and Milestones with named owners, target dates, and closure evidence requirements.

Section 7

Assessor Conduct Standards

The following conduct standards apply to every Securitique™ assessor on every engagement. They are not guidelines. They are requirements.

Independence

An assessor must not allow client preference, timeline pressure, or relationship considerations to influence a rating or finding. Ratings stand on evidence. Period.

Transparency

An assessor must document the basis for every rating and every finding in sufficient detail that a second assessor could independently verify the conclusion from the same evidence.

Objectivity

An assessor must approach every control and every finding without a predetermined conclusion. Evidence determines the rating, not the assessor's prior experience with the client or the system.

Confidentiality

An assessor must protect all client information and evidence in accordance with the engagement agreement. Assessment materials are not shared outside the engagement team without explicit client authorization.

Accuracy

An assessor must not overstate or understate a finding. The finding must reflect exactly what the evidence supports no more and no less.

Professionalism

An assessor must conduct all interviews, site visits, and client interactions with professionalism and respect. Disagreements about findings are resolved through evidence not through argument or accommodation.

Section 8

Citation and Versioning

EFAS™ is a formally versioned standard. Each version is assigned a version number and a publication date. Organizations and assessors who reference EFAS™ in proposals, reports, or other professional documents should use the following citation format.

Citation Format

Securitique™, Evidence-First Assessment Standard (EFAS™), Version 1.0, 2026. Available at securitique.info.

Versioning Policy

EFAS™ follows a major.minor versioning structure. Major versions such as Version 1.0 to Version 2.0 represent substantive changes to methodology, rating scales, or finding standards. Minor versions such as Version 1.0 to Version 1.1 represent clarifications, corrections, or additions that do not change the underlying methodology. All versions are archived and remain publicly available at securitique.info.

Current Version

The current version of EFAS™ is Version 1.0, published in 2026. Organizations assessing against EFAS™ should confirm they are referencing the current version before beginning an engagement.

A Standard Worth Following

EFAS™ was published because the cybersecurity assessment profession deserves a shared standard — one that defines what rigorous means, what defensible looks like, and what every organization receiving an assessment has a right to expect. It is not a proprietary methodology locked behind a consulting engagement. It is a public standard, freely available, openly citable, and held to the same scrutiny it demands of the assessments it governs.

Every Securitique™ engagement is governed by EFAS™. Every finding is defensible. Every rating is evidence-based. No exceptions.

"An assessment that cannot be defended is not an assessment. It is an opinion."

EFAS™ Version 1.0 Foreword | Securitique™ 2026