Skip to content

Readiness & Maturity Assessment

Run a pre-engagement PCI DSS maturity interview that scores each control 0–5 and produces a gap-to-green readiness report — before the formal ROC begins.

Updated View as Markdown

Before the formal Report on Compliance begins, Kliper lets you run a Readiness Assessment — a short, interview-based maturity review that scores a client’s PCI DSS posture on a 0–5 scale per control and produces a one-page gap-to-green report for the board. It’s the pre-engagement conversation that tells everyone where the client stands and what to fix first.

The scoring is deterministic and assessor-driven — you rate the depth of each answer; Kliper does not invent a score. The result is a repeatable maturity snapshot, not an AI guess.

Where to find it

Open a client from the Engagement Hub → Clients, then select the Readiness tab. The tab lists every readiness assessment for that client with its signal count, overall maturity, and status. Click New assessment to start an interview, or open an existing one.

The maturity scale

Every control is scored on a fixed 0–5 scale. The colors are a scoring semantic (they mean the same thing everywhere in the product), not branding.

Level Name Meaning
0 Non-existent No process; the control is absent.
1 Initial Ad-hoc, undocumented, inconsistent.
2 Established Documented and performed, but not consistently.
3 Defined Standardized, documented, and consistently followed.
4 Managed Measured and monitored; deviations are caught.
5 Optimized Continuously improved; evidence is automatic.

Defined (3) is the target line — a domain scoring below Defined becomes a lever you author a next action for at sign-off (see Closing the session).

Running the interview

Starting a new assessment opens the Readiness Interview. It’s built for a live conversation — score with the keyboard while you talk.

Pick a control

The center panel shows the current control — its number, requirement, and the question. Use the left rail to filter by dimension (Controls, Validation, Evidence, Governance, General) or jump to a requirement (R1–R12). Each requirement row shows how many of its controls you’ve covered.

Capture the answer

Optionally type what the interviewee described — observations, evidence references, or gaps — in the Notes / Evidence cited field. This is captured with the signal and feeds the report’s current-state notes.

Score the maturity

Choose a level 0–5 — the score rates the depth of the answer, not the question. Press the number keys 05 to select, then Enter to record and advance to the next unanswered control. Arrow keys move between controls.

The live compass

Across the top, the compass updates from the scoring engine as you record signals:

  • Overall maturity — the rolled-up 0–5.0 score and its tier.
  • Maturity distribution — where each domain sits on the 0–5 band, with the overall marker.
  • Weakest domain — the lowest-scoring requirement (click to jump to it).
  • Coverage — signals recorded and domains covered.

Ad-hoc observations

Not every finding maps to a scripted control. Click Ad-hoc observation to record an off-script signal — a maturity level plus a short note — that rolls into the domain you assign it to.

Closing the session

When the conversation is done, click Close session to open the sign-off dialog.

For each lever — the lowest-scoring dimension in a domain that sits below Defined (3) — you author the concrete next action that would raise it a level. The current-state note is carried from the interview; the action is yours. Blank actions are skipped, and if every assessed domain is already at Defined or above there are no levers to author.

The readiness report

From the interview (or the assessment row), open the Report — the client-facing deliverable. It renders from the same engine snapshot, so the numbers always match the interview:

  • Overall posture — the maturity tier and the 0–5 distribution.
  • Domain scores — average maturity per requirement (R1–R12).
  • Maturity matrix — a requirement × dimension grid of every recorded cell.
  • Gap-to-green — the ranked levers, each showing its current level, target level, and the next action you authored.

While the session is open the report is a Draft (a “provisional — session in progress” banner shows and figures update live). After you close the session it becomes Final. Use Export PDF to produce a print-ready copy for the client.

Was this helpful?

Report an issue with this page
Navigation

Type to search…

↑↓ navigate↵ selectEsc close