---
title: "Creating an Assessment"
description: "The New Assessment wizard — clients, report profiles, scope, carry-forward, and the QA reviewer — plus the list, table, and board views."
version: "en"
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.kliper.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Creating an Assessment

## Starting a new assessment

Open the wizard from the **New assessment** button in the top bar (available on every page), from the [Assessments](/operations/reviews) page, from any engagement (LOE), or with the command palette (`⌘K` → "New assessment"). Kliper walks you through seven short steps and creates everything the assessment needs behind the scenes.

> **Note**
>
> **Solo-friendly by design.** You never have to stop and create an engagement by hand. If the client you pick has no Letter of Engagement yet, Kliper auto-provisions a lightweight one so you can go straight from *client* to *assessment*.

## Quick create — one screen, no wizard

For the common case — same framework, another client — **Quick create** skips the wizard entirely: one screen with client, framework, and name, and the assessment exists. It **remembers your last framework and client** as defaults, so a solo assessor's next assessment is two clicks. The full wizard remains for anything that needs report profiles, carry-forward, or QA setup.

## The steps

1. **Basic info**

   Name the assessment and choose the **Owner** and, optionally, a **QA reviewer** (see below). The retired ID-prefix field is gone — assessments are identified by name.
2. **Client**

   Pick an **existing client**, or choose **New client** and enter the name, industry, region, NDA status, and primary contact. A new client record is created automatically in your Engagement Hub — you don't leave the wizard.
3. **History**

   Tell Kliper whether this is a first-time assessment or builds on prior work. Choosing **Not first time** unlocks **carry-forward** (below).
4. **Framework**

   Choose the standard and version. **PCI DSS 4.0.1** is the current standard; **3.2.1** is retired and shown greyed out.
5. **Scope & visibility**

   Set the environment scope and visibility, and optionally jump straight into scoping after creation (below).
6. **Report profiles**

   Apply your saved **firm** and **QSA** profiles to pre-fill Section 1 of the report (below).
7. **Review & create**

   Confirm the summary and create. If you chose to open scoping, you land in the scoping questionnaire; otherwise the assessment opens ready to work.

## Report profiles — fill Section 1 once

The **QSA Company** and **Lead Assessor** blocks of ROC Section 1 are identical on every report you produce. Instead of retyping them each time, save them once and apply them at creation.

- **Firm profile** (organization-wide) — set your QSAC letterhead details in **Settings → Firm profile** (admin/manager): company address, website, phone, and QSA company number. Applied assessments pre-fill the **QSA Company** block of Section 1.1.
- **QSA credentials** (per person) — set your assessor details in **Settings → Profile → QSA credentials**: lead assessor name as on your certificate, certificate number, phone, and email. Applied assessments pre-fill the **Lead Assessor** block.

On the wizard's **Report profiles** step, each profile shows a summary with an **Apply** toggle (on by default when the profile has data). Everything remains fully editable in the report afterwards — this is a starting fill, not a lock.

> **Tip**
>
> If a client has no Letter of Engagement yet, the firm profile still applies — the engagement auto-provisions and the Section 1 firm details come from your saved profile.

## Carry answers forward (re-certification)

Annual re-certifications repeat most of last year's ROC. On the **History** step, choose **Not first time**, then pick a prior assessment from **Carry answers forward from** (the list shows that client's previous assessments).

On create, Kliper copies the prior assessment's answers as a starting point, and:

- **Section 1 contact info and dates are not carried** — those belong to the new assessment period.
- Every carried answer is flagged as **needing re-verification** — the assessment opens with a re-verify banner, and carried work does **not** count toward QA progress until you touch it.
- Your per-requirement **priorities** carry over; gaps are re-detected fresh; evidence is not copied.

> **Caution**
>
> Carry-forward is a time-saver, not a rubber stamp. Re-verify each carried section before submitting for QA — the banner is there to remind you.

## Environment scope makes Cortex smarter

The **Scope** field (N/A, Cloud, On-Prem, Hybrid — with CSP/region or data-center details) is recorded on the assessment and fed into **Cortex's context**. When you ask Cortex how to test or what evidence to gather, it accounts for the environment — cloud responsibility matrices and CSP attestations for cloud, firewall configs and physical security for on-prem.

The PCI testing procedures themselves don't change per environment; the *guidance and evidence flavor* does.

## Open scoping right after creation

Creating an assessment always opens it, whichever entry point you used. Tick **Open scoping questions after creation** on the Scope step and it opens on the [scoping questionnaire](/guides/scoping-and-workbench) instead — so scoping-driven auto-fill and Not-Applicable suggestions happen immediately.

## Designate a QA reviewer

On the **Basic info** step, pick a **QA reviewer** (any admin, manager, or QA member). When the assessment is later sent to QA, that reviewer is notified directly instead of the whole review pool. Leave it unset to notify all reviewers as before. You can't assign yourself as your own QA reviewer.

## Viewing your assessments

The Assessments page offers three views, switchable from the **View** menu:

| View | Best for |
| --- | --- |
| **List** | A scannable, grouped-by-due-date list — Overdue, Due today, Upcoming, No due date. |
| **Table** | A dense, sortable grid with progress bars and owner avatars. |
| **Board** | A Kanban board by status, with drag-and-drop between columns. |

Due dates read plainly — "161 days overdue" in red, "Today" in amber, "in 30 days" — instead of raw day counts, and the framework and client are always shown alongside each assessment's name.

Source: https://docs.kliper.dev/guides/creating-assessments/index.mdx
