A compliance crosswalk that won't punish you for what nobody has measured yet
The compliance crosswalk maps one control to several frameworks at once, so evidence you gather once answers the same question in every place it gets asked. It reads what your gateways, endpoints and scans already produce, so nothing new goes into the rack and nothing already there comes out.
Seven states, and three of them walk out of the sum
The crosswalk is its own engine, separate from the RMF assessment side, and it carries seven states of its own. Four of them count toward the number: satisfied is a full point, partially satisfied is half a point, gap is zero, and in progress is also zero, because work underway isn’t evidence however well it’s going. The other three leave the calculation entirely. Manual required, not evidenced and not applicable don’t count for you and don’t count against you, and none of the three can be set by hand. That last bit is the whole design: a state that removes a control from the denominator is exactly the state somebody under audit pressure would reach for, so it isn’t there to reach for. What you see in the console is a compliance meter with a tier shield and service orders beside it, behind an acknowledgement gate.
- Satisfied full point, partially satisfied half, gap zero
- In progress scores zero, on purpose
- Three states leave the denominator instead of failing
- None of those three can be set by hand
- One control maps to several frameworks at once
- Feeds risk scoring as one of eight findings drivers
Cybersecurity in action
This is Monday morning, before anyone’s asked you anything: the weekend’s evidence has landed, two controls moved from not evidenced into the sum, and the meter now covers more of the estate than it did on Friday.
One percentage, and two people who need it to mean different things
The person running the network wants to know which gap to work on Tuesday morning. The person who signs the invoice wants a number that doesn’t fall apart the moment somebody asks a second question about it.
Evidence gets collected once
A single control usually answers the same requirement under more than one framework. The crosswalk holds that mapping, so what you gather lands everywhere it’s relevant instead of being retyped into a fourth spreadsheet at 6pm.
The list has owners, not colours
Every control that failed, came back partial or was never tested needs a POA&M before an ATO can be prepared. Open items carry a plan and a name, which is a different object from an amber square.
Not tested stays not tested
A finding that the automation didn’t validate says exactly that. The console won’t round it up to fine for you, and it won’t quietly bury it in a green bar either.
A number that survives the second question
You’ll never have to say “that 61% isn’t really 61%”. What has no evidence behind it isn’t in the sum at all, so the percentage describes the ground you’ve actually measured and the divisor tells anyone how much ground that is.
The audit story is already written down
The record shows what was assessed, in which state, against which frameworks, with a plan attached to every open item. That’s the difference between a record that survives being read closely and one that doesn’t.
No new console, no new invoice line
The crosswalk runs on evidence the platform already collects, and it feeds your risk number as one of the eight findings drivers. A compliance gap moves risk instead of sitting in a separate report that gets opened twice a year.
Three steps, and nobody gets asked for a screenshot in any of them
Here’s what actually has to happen for a compliance number to be worth reading. It starts on a laptop belonging to somebody who’s never heard of your frameworks, and it ends with you holding a record you’d be happy to hand over.
A rule gets enforced on somebody's laptop, and their day carries on
Your colleague in accounts is working, and QNova Client is applying the protection rules you set, in the background, behind the window they’re actually looking at. They can see that protection is on and what the rules are, and they get a notification when a policy changes. What they never see is a framework name, a control ID or a percentage, because compliance state is the organisation’s business and not something to hand an employee about the laptop in their bag. The important part for you is what didn’t happen: nobody emailed them asking for proof.
The same enforcement arrives in your console as evidence, already mapped
That enforcement reaches QS-WAN with everything around it the person on the device never had. You see which control it evidences, what state that control is in, and which frameworks that one control answers at the same time. You didn’t have to chase anyone, and you didn’t have to send the message that starts with “sorry to bother you”. The controls with nothing behind them show up too, sitting outside the sum with their reason on them, so you always know how much of the estate the meter is actually describing.
You decide what gets worked, and what you say when somebody asks
Now the half that’s actually yours. You work the gaps rather than the amber squares, give every failed, partial or untested control a POA&M with an owner and a severity, and let the readiness guards stop an ATO being prepared out of a state that isn’t ready for one. When the question comes from upstairs, you answer with the score and the size of what was assessed, read together, because that’s the only way either of them means anything. The assessment side runs on its own rails alongside all this, following NIST SP 800-37 Rev 2, with six ATO states and one assessment mapped to one ATO.
| Layer | What you already have | What comes in | Does it move? |
|---|---|---|---|
| […] | […] | […] | No |
| […] | […] | […] | No |
| […] | […] | […] | No |
**Buy a dashboard and let it count your blanks as failures.** The usual compliance tool puts a percentage on a slide, and then somebody in the room has to explain what the percentage doesn’t mean.
**Score what you’ve measured, and say how much that is.** The crosswalk sits on the evidence QS-WAN and QNova Client already produce, and it’s honest about its own divisor.
Host Endpoint Monitoring
Runs on telemetry from the agent on each machine. The controls it evidences join the sum; when that telemetry isn’t there, they sit outside the calculation with their reason showing, which is exactly when the denominator rule earns its keep.
Web Scanner
Scans your web applications and reports alerts, discovered URLs and technical detail. Same rule: a control with nothing behind it is declared, never quietly failed.
Risk scoring
The crosswalk feeds it as one of the eight findings drivers, so a compliance gap moves your risk number instead of living in a report of its own.
RMF assessments and POA&M
They run on separate rails from the crosswalk: a master catalogue of 25 controls, four finding states, six ATO states, and a POA&M required on every failed, partial or untested control before an ATO can be prepared.
All three numbers are company-level, and none of them measures the crosswalk. There’s no compliance number in the proof inventory: no organisations assessed, no average score, no count of controls evidenced in production. Until one exists with a source behind it, this section stays company-level and says so out loud rather than borrowing a number from somewhere else.
Bring the percentage you'd rather not explain
Tell us which compliance number you’d struggle to defend if somebody asked a second question about it, and we’ll take ours apart on a call: the seven states, which three leave the sum, and what your divisor would honestly look like on week one. You’ll leave knowing what you can prove today and what’s still a blank, which is more useful than a higher number you’d have to talk around.
What is a compliance crosswalk?
A compliance crosswalk maps one control to several frameworks at once, so a single piece of evidence answers the same requirement wherever it’s asked. In QS-WAN it runs as its own engine with seven states, and it shows up as a compliance meter with a tier shield and service orders beside it.
What happens to a control with no evidence behind it?
It leaves the calculation instead of counting as a failure. Manual required, not evidenced and not applicable are outside the sum entirely, so they don’t help your score and they don’t hurt it. The arithmetic is satisfied plus half of the partials, divided by what was actually assessed.
Can somebody mark a control not applicable to make the number look better?
No. Those three excluding states can’t be set by hand, by anyone. That’s deliberate, because a state that pulls a control out of the denominator is the first one a person under audit pressure would reach for. The trade-off is real and you should know it going in: a high score on a small denominator is still a high score on a small denominator, so read the score and the size of the assessment together.
Why can't I prepare an ATO yet?
Because a control somewhere is failed, partial or never tested, and it doesn’t have a POA&M. Every one of those needs a plan of action and milestones, with an owner and a severity, before an ATO can be prepared. There are readiness guards in front of the lifecycle for the same reason, and it follows NIST SP 800-37 Rev 2.
Does this certify us, or file anything for us?
No to both. A meter in your console is a reading of your own evidence, not an assessor’s signature, and no percentage here turns into one. Nobody at QuantumNova looks at your controls either, because this is a product rather than a managed service. It produces the record, and sending it stays with you.
Endpoint Monitoring
Where a lot of the evidence starts, before it’s mapped to anything.
Risk Scoring
Where a compliance gap goes next: one of the eight findings drivers.
Security Policy Management
The rules being enforced on the device, which is what the evidence is evidence of.
Bring the percentage you'd rather not explain
Tell us which compliance number you’d struggle to defend if somebody asked a second question about it, and we’ll take ours apart on a call: the seven states, which three leave the sum, and what your divisor would honestly look like on week one. You’ll leave knowing what you can prove today and what’s still a blank, which is more useful than a higher number you’d have to talk around.
NEWSLETTER
Get weekly tips, product news and early access, straight to your inbox.