For compliance teams assessing their own control posture.
Compliance audits, answered from your policies.
NIST CSF 2.0, SOC 2 readiness, ISO 27001 gap analysis, or your internal control checklist. Import the assessment, and every item is answered from your own documents with a citation, or flagged as a gap.
No credit card. No control mapping to build first.
The problem
The self-assessment takes longer than fixing the findings.
A framework self-assessment means walking a spreadsheet of a hundred or more control questions and, for each one, digging through the policy folder to find whether anything you wrote actually covers it. Most teams answer from memory, which produces the audit's worst outcome: a control marked in place that no document supports.
Mattercite works the other way around. Upload the policies, standards, and runbooks you already maintain, import the assessment, and each item comes back either answered with a citation to the exact passage, or marked N/A because nothing in your corpus supports it. The honest N/A is the point: that list is your gap register.
Assessments
The assessments compliance teams actually run.
| Assessment | What it is | How Mattercite handles it |
|---|---|---|
| NIST CSF 2.0 | Self-assessment across the six functions, from Govern to Recover | Import the question set as CSV or Excel. Each subcategory is answered from your policies with a citation, or flagged as a gap. |
| SOC 2 readiness | Pre-audit check of your controls against the trust services criteria | Run the readiness checklist before the auditor does. Items with no documentary support surface immediately. |
| ISO 27001 gap analysis | Annex A control-by-control review of your ISMS documentation | Import the Annex A checklist. Answers cite your ISMS documents; missing controls come back N/A, not assumed. |
| Internal audits | Your own recurring control checklist or board reporting questions | Save the checklist once, re-run it each quarter, and compare what changed as policies evolve. |
Why it holds up
Findings an auditor can trace.
- Cited, not asserted. Every answered item carries the source document and page with the supporting quote. Tracing a claim takes seconds, not a folder search.
- Gaps stay visible. Items your documents do not support come back N/A. Nothing is papered over, so the gap list is real work you can assign.
- Approval gate. Every answer is a draft until a person approves it. Nothing exports un-reviewed.
- Repeatable by construction. Update a policy and re-run the same assessment. The delta between runs is your remediation progress.
Questions
The short version.
Which compliance frameworks can I assess with Mattercite?
Any framework you can express as a list of questions: NIST CSF 2.0, SOC 2 readiness, ISO 27001 gap analysis, CIS Controls, or your own internal control checklist. Import the assessment as Excel, CSV, Word, or PDF and Mattercite answers each item from your uploaded policies.
How does Mattercite find gaps in my compliance program?
Every assessment item your documents do not support comes back as N/A with nothing invented. That N/A list is your gap register: each item is either a missing control or a control you run but never wrote down.
Can I use the results as audit evidence?
Answers are drafts until a person approves them, and each one carries the source document, page, and supporting quote. Export the approved assessment with citations so an auditor can trace every claim back to the policy that supports it.
Will my policy documents be used to train AI models?
No. Documents stay inside an isolated workspace on AWS, are never used to train models, and are never shared across workspaces. See the security overview and our subprocessor list.