Scrut generates executive-level compliance reports for every major module on the platform. Each report compiles your live platform data into a structured, downloadable PDF you can share with auditors, leadership, vendors, or other external stakeholders.
Every report opens with a cover page showing the report name, the relevant framework, vendor, or entity, and the date it was generated, followed by a table of contents and a series of detailed sections. The sections below describe what each report type covers.
Compliance Summary
Gives a single, board-ready snapshot of your organization's overall compliance health for a selected assessment period. The report includes:
Upcoming Audits: Any audits scheduled within the assessment period, or a note that none are upcoming.
Compliance Progress: A breakdown for every framework you have active (for example, ISO 27001:2022, SOC 2, SOC 2 Lite, GDPR, GDPR Lite, ISO 27701, HIPAA, HIPAA Lite, ISO 9001), showing percent complete, total controls, controls compliant, and controls non-compliant.
Cloud Security: Compliance percentage for each connected cloud provider, along with total resources scanned, resources compliant, and counts of high-risk and medium-risk resources.
Onboarding and Off-boarding: Total active employees and how many were onboarded or off-boarded during the period.
Security Campaigns: The status of ongoing security awareness or training campaigns, or a note that no data is available.
Vendor Assessment: Vendors added during the period and the status of their risk questionnaires (sent, submitted, accepted).
Framework Compliance Report
Shows detailed compliance progress for a specific framework, such as ISO 27701:2025 or HIPAA Security Rule. The report includes:
Framework Overview: completion percentages across Policy, Evidence Tasks, Tests, and Artifacts, along with total counts of requirements, policies, evidence items, controls, and automated tests linked to the framework.
Requirement Details: every requirement in the framework, grouped by category (for example, Administrative Safeguards), with the requirement description and its linked controls, policies, evidence, and automated tests.
Cloud Security Report
Documents the results of an automated scan of your cloud environment against recognized benchmarks such as the CIS Benchmark and AWS Foundations Benchmark. It includes:
Introduction: Background on the benchmark standard used and why it matters for your cybersecurity posture.
Objective: The purpose of the scan, such as identifying security vulnerabilities and misconfigurations and evaluating the effectiveness of existing controls.
Scan Methodology and Scope: The testing method used and the list of cloud accounts included in the scan, by provider, account ID, and account name.
Findings: A per-cloud-provider summary showing how many checks came back Healthy, Failing, or Ignored, plus total assets scanned and an overall compliance percentage.
Detailed Findings: A full table of every test run against each cloud account, listing the test name, the service it applies to, its status, and the number of flagged resources.
Test Details: A description of each test and, where relevant, the specific compliance controls it maps to across frameworks such as SOC 2, ISO 27001, ISO 27701, HIPAA, and GDPR.
Conclusion: A summary of the scan outcome, including whether any critical vulnerabilities were found and recommended next steps for any items needing attention.
Vendor Risk Assessment Report
Documents the full results of a risk assessment for a single third-party vendor. The report includes:
Vendor Details: The vendor's profile, category, risk tier, point of contact, and assessment scope.
Assessment Summary: A summary of the overall assessment results for that vendor.
Overview: Risk scores broken down by domain, the distribution of questions across risk levels, question review status (flagged, needing review, or accepted), and mitigation task status.
Mitigation Tasks: Every remediation task raised from the assessment, with its assignee, due date, source question, and current status.
Risks Identified: Risks flagged during the assessment, with inherent and residual risk scores, the treatment strategy, and any linked controls or mitigation tasks.
Questionnaire Details: A question-by-question breakdown of the vendor's submitted responses, including the risk score and domain for each question, reviewer comments, and any linked risks or mitigation tasks.
Audit Readiness Report
Helps identify gaps before an audit by documenting audit progress against a specific framework. The report includes:
Audit Details: The framework under audit; the number of controls or requirements in scope; the audit timeline (creation date, completion date, audit date, and observation period); auditees; audit leads; and audit scope.
Audit Summary: Audit review progress, an audit readiness breakdown (Accepted, Action Required, Needs Review), and totals for findings, requests, and corrective actions by status.
Control Details or Requirement Details: Depending on whether the audit was created for a framework or for a control, the corresponding section is included in the report. Every control or requirement covered by the audit, grouped by category, with linked policies, evidence, and automated tests, plus any related findings or requests.
Finding Details: Each audit finding, with assignees, creator, nature of finding, department, linked artifacts, and corrective actions with their criticality, due date, and assignees.
Request Details: Requests raised during the audit, structured the same way as findings.
Risk Report
Pulls data from your Risk Dashboard and Risk Register to create a unified view of your current risk landscape. The report includes:
Risk Summary: Risk status across all eight stages (Open, Assessed, Treatment in Progress, Pending Approval, Needs Revision, Treated, Monitor, and Closed), a risk heat map plotting likelihood against impact, mitigation task status, and a breakdown of treatment strategy (Accept, Avoid, Transfer, Mitigate).
Risk Register: Every risk record, with its assignee, approver, entity, domain, inherent and residual risk scores, linked controls, linked assets, and linked mitigation tasks.
Risks by Department and Risks by Category: Comparisons of inherent versus residual risk broken down by department and by risk category.
Application Security Assessment Report
Summarizes security findings from vulnerability scans performed on your applications. The report includes:
Executive Summary: The assessment objective, scope, last scan date, counts of open, registered, and accepted findings, an overall risk rating, and recommended next steps.
Engagement Overview: The in-scope applications and the parties responsible for the assessment on both your side and Scrut's side.
Approach and Methodology: The testing technique used (for example, Dynamic Application Security Testing), the tools, scan mode, scan type, verification method, and the rules or policies applied.
Vulnerability Scoring Criteria: Definitions for each severity level: Low, Medium, High, and Critical.
Summary of Findings: Open and unresolved findings, registered risk findings, and accepted or non-applicable findings, each listed by vulnerability name, severity, and count.
Detailed Findings and Recommendations: A detailed write-up for each finding, covering severity, affected resources, a description of the issue, and the recommended remediation.
Conclusion and Next Steps: Key takeaways and recommended remediation actions.
Disclaimer: Scope limitations that apply to the assessment.
Reach out to support@scrut.io or contact your CSM for further assistance.