Framework posture
A framework-by-framework view of where Wentzel Investments LLC stands across the Wentzel Compliance Baseline — both the self-attestation track (CMMC L2, CAIQ v4, GDPR, PCI SAQ-A) and the paid-certification roadmap (SOC 2 Type II, ISO/IEC 27001, ISO/IEC 42001; SOC 3 rides SOC 2). The numbers below are our own self-assessment of control readiness, not an attestation. We say Aligned / Operational, never Certified, until an independent auditor issues a report — and today that count is zero.
Adherence snapshot 2026-06-14-wcb1 · generated Sun, 14 Jun 2026 02:00:17 GMT · source: Confluence COMP / WCB / Adherence Snapshot
Two-track roadmap progress
Self-attestation track
Shippable now — no external auditor
How to read this
- Self-attestation track — frameworks we can stand behind today on our own assessment (CMMC L2 self-assessment with an SPRS score, CAIQ/CCM answer set, GDPR readiness, PCI SAQ-A). No external auditor is required for these, but they are still our attestation, not a certificate.
- Paid-certification track — SOC 2 Type II and ISO/IEC 27001/42001, where an independent auditor (nominated: Prescient Assurance) must issue the report or certificate before we describe ourselves as anything beyond Aligned. The percentages here are readiness toward that engagement.
- Per-control detail — the control-by-control matrix, evidence pointers, and live issue tracking are available to enterprise customers under NDA via the customer packet, alongside the penetration-test summary and disaster-recovery drill results.
8 frameworks tracked. Source content lives in Confluence (COMP space); this page renders the latest published adherence snapshot. Reviewing us? Reach our security team at security@wentzel.ai or see our Security controls.