The method has five stages. Four of them produce evidence. The first produces the only thing that makes evidence mean anything: a claim to test it against.
Group 0 — The declaration
Nothing is measured before you have written down what you believe to be true. This is not paperwork. A finding recorded against a claim you never made is an opinion, and an opinion is what every other assessment already sells. A finding recorded against a claim you did make is a verification, and it is the only thing an insurer or a client will accept as an answer.
The declaration is short and specific: what is exposed and what is closed; what is logged and where those logs are sent; what is backed up and how far back; who holds administrative access; and in which timezone your operations run. That last item is not a detail. Evidence from three systems in three timezones cannot be correlated unless someone writes down which clock is authoritative.
Group 1 — Measurement from outside
No access required, and nothing that a visitor to your website does not already do. What is reachable from the public internet; which administrative interfaces answer; which certificates are actually presented, and whether an ordinary client would accept them; what your DNS and mail posture reveals to anyone who looks.
This stage routinely contradicts the inventory. A service that listens on every interface is not the same as a service that is reachable, and the difference can be a factor of four in either direction. Measuring from inside the building tells you what is configured. Measuring from outside tells you what exists.
Group 2 — Evidence from configuration
Read-only access. Rules are compared against the stated intent. Administrative accounts are enumerated, including the ones nobody remembers creating. Log destinations are followed to see whether anything actually receives them. Signature freshness and patch level are established against current advisories. Configuration is fingerprinted, so that from the second engagement onward, drift becomes measurable rather than remembered.
Group 3 — Active proof
A scheduled window, your written approval, and a rollback prepared before anything begins. This is the part that separates the exercise from a questionnaire, and it is deliberately short.
Traffic is sent to a port that is supposed to be closed, and the block is observed — with a control: traffic is also sent to a port that is supposed to be open, because “nothing arrived” proves nothing unless you can show the measurement was working. Intrusion detection is triggered under controlled conditions, and the response is observed. A backup is actually restored. A log is followed to its destination and found there, or not found there.
Groups 1 and 2 can be performed by anyone with a scanner and an account. Group 3 is the reason the report is worth reading.
Group 4 — Jurisdiction and ownership
Who owns each component of the stack that defends you, under which legal system it operates, where its management plane resides, and where its telemetry is sent. Geographic location and legal jurisdiction are not the same thing. A datacentre inside the European Union, operated by an entity subject to another country’s disclosure law, satisfies one of those tests and not the other — and a review that treats them as interchangeable will reassure you about a question you were not asking.
What the method refuses to do
It does not repair. It does not monitor. It does not certify. It does not test your people, and it does not attempt to breach anything you have not explicitly declared and approved. Each of these exclusions is written into the engagement, because a document that states plainly what it did not examine is far harder to attack than one that implies it examined everything.