Go to 8. Compliance Operations
After completing a Compliance Assessment, Crucible produces a Compliance Report describing the assessment and its results.
The Compliance Report presents the assessment information in a form suitable for review and subsequent compliance activities. Producing the report does not independently establish compliance, approve an exception, accept risk, or authorize operation.
The Compliance Report identifies the assessment to which it applies.
The report can identify:
The report remains associated with the specific subject and assessment represented by its contents.
Crucible presents the results returned by the applicable assessment process.
The report can include:
The Compliance Report does not replace the provider-native results or the supporting Evidence generated under separate requirements.
The report distinguishes a completed assessment from an assessment that could not evaluate all applicable criteria.
The report can identify:
Crucible does not report an unsupported, incomplete, or failed evaluation as a successful result.
The report maintains the relationship between each reported result and the compliance criterion evaluated.
The report can identify:
This relationship allows a reviewer to determine which criterion produced each reported result.
The Compliance Report can support review by authorized people and systems.
The report format can support:
FR-COMP-003 establishes Compliance Reporting. It does not by itself prescribe a particular report format, schema, visualization, or reporting product.
The reporting result identifies:
The Compliance Report becomes an input to authorized review, remediation planning, audit, governance, and authorization-supporting activities.
| Requirement | Statement |
|---|---|
| FR-COMP-003 — Compliance Reporting |
Crucible SHALL generate Compliance Reports. |
The linked leaf requirement page remains the canonical source.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.