Compliance Coverage
Compliance coverage answers a question a framework score cannot: how much of this framework can Onam actually assess, and what is left for you?
Score versus coverage
A compliance score says what proportion of assessed controls pass. Coverage says what proportion of the framework's controls were assessed at all. Reporting the first without the second is how a framework with a third of its controls unmapped shows a reassuring score.
The view reports both: framework assessment scores and control coverage.
Why a control might not be automatically assessed
| Reason | What it means |
|---|---|
| Requires an agent | The control is evaluated at host level, not through a cloud API |
| Hardware-level | Physical or hardware controls no remote collector can reach |
| Process control | The control is about a documented process, not a configuration |
| Not applicable | The control's technology is not present in this estate |
Controls in the first three groups are classified as manual rather than reported as passing. A control nothing checked is never scored as if it passed.
Collection method
Every control records whether it is collected via API or requires an agent. This is the honest version of coverage: it tells an auditor exactly which assertions are continuously verified and which rest on a documented process.
Coverage across frameworks
Onam maps 78 frameworks. Coverage varies between them — a cloud-native benchmark maps almost entirely to automated checks, while a broad control framework like NIST 800-53 has substantial process content that no scanner can assess. The coverage view makes that difference visible per framework instead of averaging it away.
Related: Compliance for the framework list and evidence export.