Assessment frameworks
80+ assessment frameworks. 9 consulting practices.
Every framework runs an evidence-based maturity or readiness assessment from the client's own documents, scores it on the standard's own scale, ranks the gaps, and auto-generates a board-ready deck and report, with an AI interviewer to fill anything missing.
UK-regulatory coverage built in: 14 of the 80+ frameworks are UK-specific, a differentiator for firms advising regulated UK clients.
Cybersecurity · Data & AI · Technology · Finance & Risk · Operations · Growth · Strategy & Transformation · Sustainability · Human Capital
How every assessment works
Standards-aligned. Evidence-grounded. Exec-ready.
1 · Evidence in
Upload the client's documents: policies, reports, data. An AI interviewer asks targeted follow-ups to fill anything missing.
2 · Scored on the standard
Every dimension is scored on the framework's own scale, with each score traceable to the evidence behind it, and gaps ranked by severity.
3 · Board-ready out
A board-ready slide deck and HTML report are generated automatically: executive summary, maturity landscape and a sequenced plan.
Browse by practice
Frameworks by consulting practice
Nine practices, 80+ frameworks. Open a practice to see how each one is scored.
SOC 2 (Trust Services Criteria)
Run a SOC 2 gap assessment across the five Trust Services Criteria before the audit.
ISO/IEC 27001 ISMS Readiness
Gauge ISMS readiness against the Annex A controls before committing to certification.
NIST CSF 2.0
Score maturity across all six CSF 2.0 functions, evidenced from the client's own controls.
PCI DSS v4.0
Assess cardholder-data security against the PCI DSS v4.0 requirements and SAQ scope.
CIS Controls v8
Benchmark the 18 CIS Controls and implementation groups against real evidence.
Zero Trust (CISA ZTMM)
Rate zero-trust maturity across the five CISA pillars and the gaps to close first.
Cyber Essentials (NCSC)
Check readiness against the five NCSC Cyber Essentials control themes before assessment.
NCSC Cyber Assessment Framework (CAF)
Assess against the 14 CAF principles for NIS-regulated and critical services.
NHS Data Security & Protection Toolkit (DSPT)
Evidence the NHS DSPT standards for health and care organizations.
ISO/IEC 27701 Privacy Information Management
Extend an ISMS to privacy and assess PIMS readiness against ISO 27701.
ISO 22301 Business Continuity
Gauge business-continuity management-system readiness against ISO 22301.
OWASP SAMM
Benchmark software-assurance maturity across the OWASP SAMM business functions.
Third-Party & Supply-Chain Risk
Assess vendor and supply-chain cyber risk and due-diligence maturity.
ISO/IEC 42001 AI Management System
Assess AI management-system readiness against ISO 42001 before certification.
NIST AI Risk Management Framework
Score AI risk practice across the NIST AI RMF Govern, Map, Measure and Manage functions.
EU AI Act Readiness
Classify AI systems by risk tier and assess obligations under the EU AI Act.
AI Governance & Responsible AI Maturity
Measure responsible-AI maturity across governance, risk, transparency and oversight.
Data Management Maturity (DAMA-DMBOK)
Score the data discipline against the DAMA-DMBOK knowledge areas: governance, quality, architecture and operations.
UK AI Regulation (DSIT Principles & Assurance)
Check alignment to the UK's five AI-regulation principles and assurance expectations.
UK GDPR & Data Protection / ICO Accountability
Assess UK GDPR accountability against the ICO's accountability framework.
DCAM Data Management Capability
Benchmark capability against the EDM Council DCAM model, the data-governance standard favored in financial services.
MLOps & Model Operations Maturity
Assess the maturity of model deployment, monitoring and lifecycle operations.
Analytics & BI Maturity
Measure analytics and BI maturity from reporting to embedded decision intelligence.
Data Strategy Assessment
Evaluate data maturity across governance, quality, architecture, analytics and culture.
Data & AI Governance Assessment
Assess data governance, security, quality, sharing and AI ethics across the data lifecycle.
Cloud Well-Architected Review
Review workloads against the cloud provider's Well-Architected pillars: reliability, security, cost and more.
DevOps & DORA Metrics
Benchmark delivery performance against the core DORA metrics and DevOps practice.
Site Reliability Engineering (SRE)
Assess reliability practice: SLOs, error budgets, incident response and toil reduction.
FinOps Cloud Financial Management
Rate cloud cost-management maturity against the FinOps Framework capabilities.
ITIL 4 Service Management
Assess service-management maturity across the ITIL 4 practices.
GDS Service Standard & Technology Code of Practice
Check public-sector services against the GDS Service Standard and Technology Code of Practice.
NHS Digital Technology Assessment Criteria (DTAC)
Evidence the NHS DTAC criteria for digital health technology.
Platform Engineering Maturity
Assess internal developer platform and self-service capability maturity.
Enterprise Architecture (TOGAF)
Benchmark enterprise-architecture capability against the TOGAF framework.
Digital Accessibility (WCAG 2.2)
Assess digital accessibility conformance against WCAG 2.2 success criteria.
Green Software & Sustainable IT
Measure sustainable-software practice against the Green Software Foundation principles.
Finance Function & FP&A Maturity
Score the finance function and FP&A across planning, reporting and partnering.
Enterprise Risk Management (COSO ERM)
Assess enterprise risk management against the COSO ERM framework.
Operational Resilience (EU DORA)
Gauge digital operational resilience readiness against EU DORA.
FCA Operational Resilience (PS21/3)
Map important business services and impact tolerances to FCA PS21/3.
FCA Consumer Duty
Assess Consumer Duty outcomes: products, price and value, understanding and support.
Senior Managers & Certification Regime (SM&CR)
Check SM&CR readiness across responsibilities, certification and conduct rules.
UK Corporate Governance Code (FRC)
Evidence compliance with the FRC UK Corporate Governance Code.
AML & Financial Crime
Assess anti-money-laundering and financial-crime controls against regulatory expectations.
MiFID II
Check investment-firm conduct and reporting readiness against MiFID II.
PSD2 & Open Banking
Assess payment-services and open-banking compliance against PSD2.
BCBS 239 Risk Data Aggregation
Rate risk-data aggregation and reporting capability against BCBS 239.
Solvency II
Assess insurer capital, governance and reporting readiness against Solvency II.
IFRS 9 / IFRS 17
Check accounting readiness for IFRS 9 financial instruments and IFRS 17 insurance contracts.
ISO 37001 / 37301 Anti-Bribery & Compliance
Assess anti-bribery and compliance management systems against ISO 37001 and ISO 37301.
Operational Excellence & Lean Maturity
Benchmark operational excellence and Lean maturity across the value stream.
Supply Chain Resilience & Maturity
Score supply-chain resilience, visibility and risk readiness.
ISO 9001 Quality Management
Assess quality-management-system readiness against ISO 9001.
ISO 45001 Occupational Health & Safety
Gauge OH&S management-system readiness against ISO 45001.
Industry 4.0 / Smart Manufacturing
Benchmark digital-manufacturing and Industry 4.0 capability maturity.
S&OP / Integrated Business Planning
Assess sales & operations planning and IBP process maturity.
Food Safety (BRCGS)
Check food-safety management readiness against the BRCGS global standard.
CQC Fundamental Standards
Evidence readiness against the CQC fundamental standards for care providers.
Clinical Safety (DCB0129 / DCB0160)
Assess clinical-risk management for health IT against DCB0129 and DCB0160.
ISO 13485 Medical Devices
Assess medical-device quality-management readiness against ISO 13485.
HIPAA
Assess protected-health-information safeguards against the HIPAA Security and Privacy Rules.
HL7 FHIR Interoperability
Benchmark healthcare data interoperability maturity against HL7 FHIR.
Customer Experience Maturity
Measure CX maturity across strategy, journey, measurement and culture.
Revenue Operations (RevOps) Maturity
Assess RevOps alignment across sales, marketing and customer success.
Marketing & Martech Maturity
Benchmark marketing capability and martech stack maturity against demand goals.
Sales Effectiveness
Assess sales process, enablement and pipeline-management maturity.
Customer Success Maturity
Measure customer-success capability across onboarding, retention and expansion.
Pricing & Monetization Maturity
Assess pricing strategy, packaging and monetization discipline.
Digital Transformation Readiness
Gauge readiness to transform across strategy, capability, technology and culture.
Innovation Management (ISO 56001)
Assess innovation-management-system maturity against ISO 56001.
M&A Integration Readiness
Score post-merger integration readiness across people, process and systems.
Operating Model Assessment
Assess how strategy, processes, technology, people and governance work together to deliver outcomes.
Strategy & Execution Assessment
Assess how well strategy is translated into execution, from define through embed.
Business Model Canvas
Review the business model across the nine building blocks, from value propositions to cost structure.
ESG & Sustainability Maturity
Score ESG and sustainability maturity across environment, social and governance.
CSRD / ESRS Readiness
Assess readiness for CSRD reporting against the ESRS disclosure standards.
ISSB / IFRS S1 & S2 (incorporating TCFD)
Check climate and sustainability-disclosure readiness against the ISSB IFRS S1 and S2 standards, which now carry the former TCFD recommendations.
UK Sustainability Disclosure (SDR & SECR)
Check readiness for UK SDR and SECR climate and sustainability disclosure.
GHG / Carbon Accounting
Assess greenhouse-gas accounting maturity across Scope 1, 2 and 3 emissions.
ISO 14001 Environmental Management
Assess environmental-management-system readiness against ISO 14001.
B Corp Readiness
Score readiness against the B Impact Assessment for B Corp certification.
Organizational Health
Assess organizational health across leadership, culture, capability and engagement.
Change Management (ADKAR)
Measure change readiness and adoption capability across the ADKAR stages.
Agile & SAFe Maturity
Benchmark agile delivery and scaled-agile (SAFe) maturity across teams.
PMO & Portfolio Maturity (P3M3)
Assess project, program and portfolio management capability against P3M3.
Diversity, Equity & Inclusion (DEI)
Score DEI maturity across representation, inclusion and accountability.
Product Operating Model
Assess the shift to a product-led operating model and team topology.
UK regulatory coverage
Built for regulated UK clients.
From FCA Consumer Duty and SM&CR to Cyber Essentials, NHS DSPT/DTAC and UK Sustainability Disclosure, assess against the UK rules your clients are held to, scored on each standard's own scale.
- Financial services: FCA Operational Resilience, Consumer Duty, SM&CR, FRC Governance Code
- Public sector & health: GDS Service Standard, NHS DSPT, NHS DTAC
- Data, AI & ESG: UK GDPR/ICO, UK AI regulation (DSIT), UK SDR & SECR

Questions
Frequently asked
What is Celeredge?
Celeredge is an AI-native operating system for consulting firms. It runs evidence-based assessments against a library of 80+ consulting-grade frameworks across 9 practice areas. Clients upload evidence, the platform scores it against each framework's controls or maturity model, an AI interviewer surfaces gaps, and it generates client-ready decks and detailed reports.
How many assessment frameworks does Celeredge support?
Celeredge ships 80+ standards-aligned assessment frameworks across 9 consulting practices, including 14 UK-specific regulatory frameworks.
What does a framework assessment deliver?
Each framework runs an evidence-based maturity or readiness assessment from the client's own documents, scores it on the standard's own scale, ranks the gaps by severity, and auto-generates a board-ready slide deck and detailed report, with an AI interviewer to fill any missing evidence.
Which frameworks does Celeredge cover?
Flagship coverage includes SOC 2, ISO 27001, NIST CSF 2.0 and PCI DSS (cybersecurity); ISO 42001, the NIST AI RMF and the EU AI Act (data & AI); Cloud Well-Architected, SRE, FinOps and ITIL 4 (technology); COSO ERM, the EU DORA regulation, FCA Consumer Duty and SM&CR (finance & risk); plus operations, sustainability (CSRD/ESRS, ISSB/IFRS S1 & S2), growth, human capital and transformation frameworks.
Does Celeredge cover UK regulatory frameworks?
Yes. UK-specific coverage includes Cyber Essentials, NCSC CAF, NHS DSPT and DTAC, the GDS Service Standard, FCA Operational Resilience (PS21/3), FCA Consumer Duty, SM&CR, the UK Corporate Governance Code, UK GDPR/ICO accountability, UK AI regulation (DSIT), UK Sustainability Disclosure (SDR & SECR) and CQC.
Can we run our own frameworks?
Yes. Author your own frameworks, with dimensions, questions and scoring bands, starting from an open standard and adding proprietary dimensions, then run the same method firm-wide. Framework authoring →
See a framework run on real data.
Pick any of the 80+ frameworks and we'll score it live from a client's own documents.