uSecure's GAP analysis is a roughly 15-minute questionnaire that identifies each user's weakest security areas and rolls the results into a Risk Score - an algorithm scoring each user (and the organisation as a whole) out of 900, split into five tiers from Very High to Very Low, with a breakdown by group or department. The resulting Human Risk Report is built to be exported and shared with leadership, auditors or clients in an executive-ready format, tracking course participation, quiz grades and risk score over time.
That's a genuinely useful trend-line tool - it shows whether an organisation's human risk is improving. What it isn't, based on the public materials we reviewed, is an assessment mapped to a named compliance framework's specific controls. The framework list uSecure publishes elsewhere (ISO 27001, GDPR, DORA, NIS2, HIPAA, PCI DSS, CIS Controls, SOC 2) is a separate marketing claim from the GAP analysis and Risk Score tool itself.
Cyber Aware's gap assessments map directly to Essential 8 and SMB1001 controls, branded to the MSP, so the evidence an Australian client hands an auditor is framework-specific from the first report.