Skip to content
Foxx Cyberfoxxcyber/docs

Recording Findings

Score assessment objectives and record findings on each control.

Findings are recorded per assessment objective on each control's detail page. This page covers how to navigate the controls, score objectives, and save control-level findings — the tool records what you decide; the assessment judgment is yours.

Assessment mode

While the Assess phase is active, the workspace shows an assessment-mode banner:

  • Live Assessment Mode with an ACTIVE badge means the OSC's package is locked read-only and you can record official assessments. The lead assessor can click Pause Lock (with a confirmation dialog) if the OSC needs to make a change mid-assessment.
  • Assessment Mode Paused with an UNLOCKED badge means the customer can currently edit their package. The lead can click Resume Lock to re-lock it.

The Controls tab

In the engagement, open the Assessment section and click Controls. The Security Requirements card lists every control:

  • Status count badges at the top (Met, Not Met, In Progress, Not Started, N/A) double as filters — click one to filter, click again to clear.
  • The Search controls... box and the family dropdown (All Families) narrow the list; Clear filters resets everything.
  • Columns: Control ID, Title, Family, Status, Points, Objectives, Evidence. Click a column header to sort.
  • Click any row to open that control's detail page.

The Status column shows the OSC's self-assessment status for the control; the Objectives column shows your progress ("n / m met").

The control detail page

Each control page is a two-column split:

  • Left — OSC Self-Assessment (Read-Only): the OSC's per-objective implementation data, control-level Implementation Notes, the Evidence list (with Review and Download buttons per file), and a collapsible Requirement Details card with the NIST SP 800-171 requirement text.
  • Right — C3PAO Assessment: the Assessment Objectives cards where you record your results, and the Assessor Findings card for control-level findings.

Navigation at the top shows Control n of N with previous/next buttons, Back to Controls, and a Reader button that opens the split-screen Evidence Reader in a new tab.

Score an objective

  1. In the Assessment Objectives card, click an objective row to expand it.
  2. Record your result:
    • ScoreNot Assessed, Met, Not Met, or N/A.
    • Time to Assess (minutes).
    • Artifacts Reviewed — check the evidence files you examined.
    • Interviews — who you interviewed (semicolon-separated).
    • Examine Description and Test Description — what you examined and tested.
    • Dependent ESP — select an external service provider if the objective is inherited.
    • My Questions for OSC Interview — private interview prep notes, not visible to the OSC.
    • Findings — your findings for this objective.
  3. Click Save. A toast confirms "Objective assessment saved".

The fields on this card feed the eMASS workbook columns directly — filling them in as you go means the eMASS export is complete when you get there.

If someone else saved the same objective while you had it open, saving shows a conflict error and asks you to refresh — the client uses version checks to prevent silently overwriting a colleague's work.

Control-level assessor findings

The Assessor Findings card at the bottom of the right column holds findings for the control as a whole. With assessment mode active, type into Assessment Findings & Recommendations and click Save Findings. These notes appear prominently on the customer's control view once delivered.

Track progress

  • The Progress tab in the Assessment section shows completion across all controls and objectives.
  • The Review tab shows the Findings Review queue, where the lead reviews recorded findings and marks each one Approve, Needs Revision, or Reject, and the Notes panel — click Add note to keep engagement-scoped living notes; every edit and delete is tracked with a revision history.

Last updated July 29, 2026