dido:02-crusible:08-compliance-and-authorization-operations:08-03-produce-compliance-reports

8.3 Produce Compliance Reports

Go to 8. Compliance Operations

After completing a Compliance Assessment, Crucible produces a Compliance Report describing the assessment and its results.

The Compliance Report presents the assessment information in a form suitable for review and subsequent compliance activities. Producing the report does not independently establish compliance, approve an exception, accept risk, or authorize operation.

The Compliance Report identifies the assessment to which it applies.

The report can identify:

  • The assessment identifier
  • The assessment subject
  • The subject revision
  • The selected Compliance Baseline
  • The applicable compliance criteria
  • The assessment provider
  • The provider revision
  • The assessment time
  • The assessment status

The report remains associated with the specific subject and assessment represented by its contents.

Crucible presents the results returned by the applicable assessment process.

The report can include:

  • The criteria evaluated
  • The result associated with each evaluated criterion
  • Criteria the provider could not evaluate
  • Incomplete or failed evaluations
  • Assessment errors
  • Summary information derived from the assessment results
  • References to associated Compliance Evidence Artifacts

The Compliance Report does not replace the provider-native results or the supporting Evidence generated under separate requirements.

The report distinguishes a completed assessment from an assessment that could not evaluate all applicable criteria.

The report can identify:

  • Unsupported criteria
  • Unsupported subject types
  • Unsupported operating systems
  • Missing assessment inputs
  • Provider failures
  • Incomplete assessment results
  • Criteria for which no determination was produced

Crucible does not report an unsupported, incomplete, or failed evaluation as a successful result.

The report maintains the relationship between each reported result and the compliance criterion evaluated.

The report can identify:

  • The criterion identifier
  • The criterion source
  • The applicable Compliance Baseline
  • The Baseline revision
  • The assessment result
  • The assessment provider
  • Any associated explanatory information
  • Any reference to supporting Evidence

This relationship allows a reviewer to determine which criterion produced each reported result.

The Compliance Report can support review by authorized people and systems.

The report format can support:

  • Human-readable presentation
  • Machine-readable processing
  • Comparison of assessment results
  • Review of unsupported or incomplete evaluations
  • Association with Compliance Evidence Artifacts
  • Subsequent compliance and authorization-supporting activities

FR-COMP-003 establishes Compliance Reporting. It does not by itself prescribe a particular report format, schema, visualization, or reporting product.

The reporting result identifies:

  • The Compliance Report
  • The assessment represented by the report
  • The assessed subject
  • The selected Compliance Baseline and criteria
  • The assessment provider
  • The reported assessment results
  • Any unsupported, incomplete, or failed evaluation
  • References to associated Compliance Evidence Artifacts, when available
  • The report-generation status

The Compliance Report becomes an input to authorized review, remediation planning, audit, governance, and authorization-supporting activities.

Requirement Statement
FR-COMP-003 — Compliance Reporting

Crucible SHALL generate Compliance Reports.

The linked leaf requirement page remains the canonical source.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/02-crusible/08-compliance-and-authorization-operations/08-03-produce-compliance-reports.txt
  • Last modified: 2026/08/01 07:31
  • by nick_dido