The Cybersecurity Framework 2.0 organizes outcomes into six Functions — Govern, Identify, Protect, Detect, Respond, Recover — each broken into Categories and Subcategories. Pentr produces signed evidence mapped to the Subcategories a penetration test can substantiate, in the outcomes language your risk team already reports in.
Each row is a CSF 2.0 Subcategory, the phase in the agent that produces evidence for it, and the artifacts the locker holds for your risk team.
Scope, rules of engagement, and consent sealed up front.
Resolves hosts and services into an asset inventory.
Prioritises threats and vulnerabilities into risk.
Validates and records asset vulnerabilities per finding.
Proves whether access-control outcomes actually hold.
Captures whether monitoring detected the agent's activity.
sha-256 chain signed at seal time. Risk-register ready.
Plug in a scope. The agent runs all seven PTES phases and seals evidence mapped to the CSF 2.0 Subcategories your risk team reports against.