Skip to content

Creating an Assessment

The New Assessment wizard — clients, report profiles, scope, carry-forward, and the QA reviewer — plus the list, table, and board views.

Updated View as Markdown

Starting a new assessment

Open the wizard from the New assessment button in the top bar (available on every page), from the Assessments page, from any engagement (LOE), or with the command palette (⌘K → “New assessment”). Kliper walks you through seven short steps and creates everything the assessment needs behind the scenes.

Quick create — one screen, no wizard

For the common case — same framework, another client — Quick create skips the wizard entirely: one screen with client, framework, and name, and the assessment exists. It remembers your last framework and client as defaults, so a solo assessor’s next assessment is two clicks. The full wizard remains for anything that needs report profiles, carry-forward, or QA setup.

The steps

Basic info

Name the assessment and choose the Owner and, optionally, a QA reviewer (see below). The retired ID-prefix field is gone — assessments are identified by name.

Client

Pick an existing client, or choose New client and enter the name, industry, region, NDA status, and primary contact. A new client record is created automatically in your Engagement Hub — you don’t leave the wizard.

History

Tell Kliper whether this is a first-time assessment or builds on prior work. Choosing Not first time unlocks carry-forward (below).

Framework

Choose the standard and version. PCI DSS 4.0.1 is the current standard; 3.2.1 is retired and shown greyed out.

Scope & visibility

Set the environment scope and visibility, and optionally jump straight into scoping after creation (below).

Report profiles

Apply your saved firm and QSA profiles to pre-fill Section 1 of the report (below).

Review & create

Confirm the summary and create. If you chose to open scoping, you land in the scoping questionnaire; otherwise the assessment opens ready to work.

Report profiles — fill Section 1 once

The QSA Company and Lead Assessor blocks of ROC Section 1 are identical on every report you produce. Instead of retyping them each time, save them once and apply them at creation.

  • Firm profile (organization-wide) — set your QSAC letterhead details in Settings → Firm profile (admin/manager): company address, website, phone, and QSA company number. Applied assessments pre-fill the QSA Company block of Section 1.1.
  • QSA credentials (per person) — set your assessor details in Settings → Profile → QSA credentials: lead assessor name as on your certificate, certificate number, phone, and email. Applied assessments pre-fill the Lead Assessor block.

On the wizard’s Report profiles step, each profile shows a summary with an Apply toggle (on by default when the profile has data). Everything remains fully editable in the report afterwards — this is a starting fill, not a lock.

Carry answers forward (re-certification)

Annual re-certifications repeat most of last year’s ROC. On the History step, choose Not first time, then pick a prior assessment from Carry answers forward from (the list shows that client’s previous assessments).

On create, Kliper copies the prior assessment’s answers as a starting point, and:

  • Section 1 contact info and dates are not carried — those belong to the new assessment period.
  • Every carried answer is flagged as needing re-verification — the assessment opens with a re-verify banner, and carried work does not count toward QA progress until you touch it.
  • Your per-requirement priorities carry over; gaps are re-detected fresh; evidence is not copied.

Environment scope makes Cortex smarter

The Scope field (N/A, Cloud, On-Prem, Hybrid — with CSP/region or data-center details) is recorded on the assessment and fed into Cortex’s context. When you ask Cortex how to test or what evidence to gather, it accounts for the environment — cloud responsibility matrices and CSP attestations for cloud, firewall configs and physical security for on-prem.

The PCI testing procedures themselves don’t change per environment; the guidance and evidence flavor does.

Open scoping right after creation

Creating an assessment always opens it, whichever entry point you used. Tick Open scoping questions after creation on the Scope step and it opens on the scoping questionnaire instead — so scoping-driven auto-fill and Not-Applicable suggestions happen immediately.

Designate a QA reviewer

On the Basic info step, pick a QA reviewer (any admin, manager, or QA member). When the assessment is later sent to QA, that reviewer is notified directly instead of the whole review pool. Leave it unset to notify all reviewers as before. You can’t assign yourself as your own QA reviewer.

Viewing your assessments

The Assessments page offers three views, switchable from the View menu:

View Best for
List A scannable, grouped-by-due-date list — Overdue, Due today, Upcoming, No due date.
Table A dense, sortable grid with progress bars and owner avatars.
Board A Kanban board by status, with drag-and-drop between columns.

Due dates read plainly — “161 days overdue” in red, “Today” in amber, “in 30 days” — instead of raw day counts, and the framework and client are always shown alongside each assessment’s name.

Was this helpful?

Report an issue with this page
Navigation

Type to search…

↑↓ navigate↵ selectEsc close