Prosecution Insights
Last updated: October 04, 2026
Application No. 18/359,183

SYSTEMS AND METHODS FOR ASSESSING CYBERSECURITY EFFICACY OF ENTITIES AGAINST COMMON CONTROL AND MATURITY FRAMEWORKS USING EXTERNALLY-OBSERVED DATASETS

Non-Final OA §103
Filed
Jul 26, 2023
Priority
Jul 26, 2022 — provisional 63/392,179
Examiner
HAJIABBASI, AMIR MAHDI
Art Unit
2407
Tech Center
2400 — Computer Networks
Assignee
Bitsight Technologies Inc.
OA Round
3 (Non-Final)
87%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
93%
With Interview

Examiner Intelligence

Grants 87% — above average
87%
Career Allowance Rate
27 granted / 31 resolved
+29.1% vs TC avg
Moderate +6% lift
Without
With
+6.1%
Interview Lift
resolved cases with interview
Typical timeline
2y 7m
Avg Prosecution
7 currently pending
Career history
40
Total Applications
across all art units

Statute-Specific Performance

§101
4.2%
-35.8% vs TC avg
§103
61.8%
+21.8% vs TC avg
§102
11.8%
-28.2% vs TC avg
§112
18.1%
-21.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 31 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1-5, 7-13, 15-19, and 21-23 are pending. Claims 6, 14, and 20 are cancelled. Claims 1 and 15 are independent. Claims 1, 2, 15, and 16 are amended. Claims 21-23 are new. Amendments to the claims have been accepted. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 04/20/2026 has been entered. Information Disclosure Statement The information disclosure statement (IDS) submitted on 04/20/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Response to Arguments Applicant’s arguments, see pp. 8-11 (pp. 1-4 of Remarks), filed 4/20/2026, with respect to claims 1-4, 7-10, 12, 13, and 15-18 under 35 U.S.C. § 103 under Petersen in view of Baragaba and Simpson have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of Berger in view of Caithness. Applicant’s arguments, see p. 11 (p. 4 of Remarks), filed 4/20/2026, with respect to claims 5, 11, and 19 under 35 U.S.C. § 103 under Petersen in view of Baragaba, Simpson and Makovsky have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of Berger in view of Caithness. Claim Rejections - 35 USC § 103 The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action. Claim(s) 1-4, 7-10, 13, 15-18, and 21-23 is/are rejected under 35 U.S.C. 103 as being unpatentable over Berger (Berger et al., US 11757907 B1) in view of Caithness (CAITHNESS, US 20230075649 A1). Regarding claim 1 and substantially claim 15, Berger teaches a computer-implemented method for determining one or more control insights corresponding to an entity, the method comprising: receiving one or more event datasets corresponding to a plurality of cybersecurity events associated with an entity during a first time period (43:41-57), wherein at least one cybersecurity event of the plurality of cybersecurity events is derived from data collected by at least one of a service provider entity or a third-party entity different from the entity (4:18-24, 7:33-45: the target network is accessed and scanned remotely by network service provider that provides the network infrastructure and services for the entity, separate to the entity); enriching the one or more event datasets with a plurality of indicators mapped to the plurality of cybersecurity events; comparing the plurality of indicators of the one or more enriched event datasets to a plurality of rules; determining, based on the comparison of the plurality of indicators of the one or more enriched event datasets and the plurality of rules, the one or more control insights corresponding to the entity (4:64-5:19: scanned data regarding cybersecurity event data and vulnerabilities on the network is used to determine the status of cybersecurity controls. 13:31-46: scanned event/vulnerability data are compared to detection rules that specify the characteristics of events to be added. 15:7-24:, the event data analyzed against the criteria of the rules is enriched data, enriched by log data related to the events), wherein at least one rule of the plurality of rules is defined by (i) a rule type and (ii) a first subset of the plurality of indicators that is provided as an input to the at least one rule (13:55-61, 15:25-32: detection rules have different types and criteria for detecting abnormal events, such as three unsuccessful login attempts being suspicious (one rule type) or any number of login attempts at 2AM (another rule type), and there are different subsets of events, examples of such being successful or unsuccessful logins), wherein each of the one or more control insights provides an indication of a state of a respective cybersecurity control mechanism of one or more cybersecurity control mechanisms corresponding to the entity (17:34-54), wherein at least one control insight of the one or more control insights comprises (i) a natural language description of the state of the respective cybersecurity control mechanism, and (ii) a positive, neutral, or negative assessment of the state of the respective cybersecurity control mechanism (17:46-54, 19:17-33: analysis of the scan data (the sequential results being one or more control insights) is used to adjust the cybersecurity control factor score (state of the control mechanism) either positively, negative, or not at all (positive, neutral, negative). 18:8-11, the assessment responses that manage cybersecurity factors can be described with natural language processing); and generating for display, based on the one or more control insights, an action that when executed by the entity is configured to improve a state of at least one cybersecurity control mechanism of the one or more cybersecurity control mechanisms, wherein the action is determined based on a control framework corresponding to the at least one cybersecurity control mechanism (18:34-41, "As another example, threat analysis and remediation recommendation may be applied or adapted to analyze user responses, cybersecurity factor scores, and cybersecurity framework compliance results, and then provide guidance on actions that can be taken to improve cybersecurity framework compliance. The results of the analysis using such machine leaning models can be presented to a user."). Berger does not explicitly teach that at least one cybersecurity event of the plurality of cybersecurity events is derived from externally-originated data collected by at least one of a service provider entity or a third-party entity different from the entity, nor does Berger explicitly teach enriching, based on a respective event type corresponding to each of the plurality of cybersecurity events, the one or more event datasets with a plurality of indicators mapped to the plurality of cybersecurity events. In an analogous art, Caithness teaches receiving one or more event datasets corresponding to a plurality of cybersecurity events associated with an entity during a first time period ([0066], [0118]: collected network and endpoints events (one or more event datasets corresponding to a plurality of cybersecurity events) are captured, where they are related to each other via a time window. [0080], [0088]: the network and endpoint events are related to specific entity), wherein at least one cybersecurity event of the plurality of cybersecurity events is derived from externally-originated data collected by at least one of a service provider entity or a third-party entity different from the entity ([0064], [0086], "… in addition one or more server endpoints can also be provided. By way of example, a server 312g is shown connected to the network infrastructure 302, which can provide any desired service or services within private network 300. Although only one server is shown, any number of server endpoints can be provided in any desired configuration.": endpoint agents that collect endpoint event data for the network in question can come from (externally-originated) a server endpoint (service provider, third-party entity different from the entity). See also [0094]); and enriching, based on a respective event type corresponding to each of the plurality of cybersecurity events, the one or more event datasets with a plurality of indicators mapped to the plurality of cybersecurity events ([0079]: event data is enriched with enrichment data (indicators) relevant to the event (relevancy is the type) with potential significance in a cybersecurity context, such as flagging a known malicious file name or IP address). Berger and Caithness are analogous arts, as both deal with service providers enriching cybersecurity event data to manage cybersecurity systems. One of ordinary skill in the art prior to the effective filing date of the claimed invention could modify Berger using Caithness to have some of the event data collected by the service provider be externally originated (such as coming from a server endpoint) and have the event data be enriched by the log data according by its relevance to the event (event type) by implementing the instructions taught by Caithness into the invention of Berger with predictable results. It would be obvious to one of ordinary skill in the art to do so because it allows for detecting and reporting security threats using the state of endpoints of the network (such as a server endpoint) (Caithness, [0073], [0086]), and because the enrichment data would augment to the event data (Caithness, [0079]) Regarding Claim 2 and substantially claim 16, Berger in view of Caithness teaches the method of claim 1, wherein: (i) the plurality of cybersecurity events are associated with one or more computing systems corresponding to the entity (43:13-29, "The information regarding the target network may also identify the portions of the target network to be scanned by the instance of the cybersecurity assessment system.": the cybersecurity events scanned from the target network chosen by the entity), and (iii) at least one cybersecurity event of the plurality of cybersecurity events is derived from internal data provided by the entity, the internal data comprising one or more of domain name system (DNS) log data (33:11-16), authentication log data, netflow log data (47:16-17), web proxy log data, and firewall log data. Caithness further teaches (ii) the externally-originated data comprises one or more of malware sinkhole data, honeypot data, port scanning data, vulnerability scanning data, service configuration scanning data, actively and/or passively collected domain name system (DNS) data, advertising and marketing telemetry data, application-based endpoint behavior data (Caithness, [0064], [0096])(see claim 1 for motivation to combine), and mobile application security assessment result data. Regarding Claim 3 and substantially claim 17, Berger in view of Caithness teaches the method of claim 1. Caithness further teaches determining a plurality of event types for the plurality of cybersecurity events, wherein each cybersecurity event is mapped to a respective event type of the plurality of event types that identifies the cybersecurity event (Caithness, [0079]: event data is enriched with enrichment data (indicators) relevant to the event (relevancy is the type) with potential significance in a cybersecurity context, such as flagging a known malicious file name or IP address) (see claim 1 for motivation to combine). Regarding Claim 4 and substantially claim 18, Berger in view of Caithness teaches the method of claim 1, wherein each cybersecurity event is mapped to a respective subset of the plurality of indicators comprising contextual information for the cybersecurity event (Berger, 15:7-24:, the event data analyzed against the criteria of the rules is enriched data, enriched by log data related to the events (contextual information for the cybersecurity event)). Regarding Claim 7, Berger in view of Caithness teaches the method of claim 1, wherein the control framework is selected from the group consisting of: a Center for Internet Security Top 20 Critical Security Controls (CIS20) framework, a National Institute of Standards and Technology (NIST) framework (Berger, 17:8-16, "In one specific non-limiting embodiment, a cybersecurity framework may be based at least partly on a standardized set of requirements, such as National Institute of Standards and Technology (“NIST”) 800-171, NIST 800-53, the Payment Card Industry Data Security Standard (“PCI DSS”), International Organization for Standardization/International Electrotechnical Commission (“ISO/IEC”) 27001, or the Center for Internet Security (“CIS”) Critical Security Controls.") Regarding Claim 8, Berger in view of Caithness teaches the method of claim 1, wherein the at least one rule of the plurality of rules is further defined based on at least one characteristic corresponding to the entity and by (i) the rule type, (ii) the first subset of the plurality of indicators, and (iii) at least one threshold value (Berger, 13:55-61, 15:25-32: detection rules have different types and criteria for detecting abnormal events, such as three unsuccessful login attempts being suspicious (one rule type) or any number of login attempts at 2AM, since there are normally no logins at that time (another rule type, defined based on at least one characteristic corresponding to the entity), and there are different subsets of events, examples of such being successful or unsuccessful logins. 18:65-19:3, "In some embodiments, the rules-based analysis may be implemented as a series of rules, applied in a predetermined or dynamically determined sequence, in which a data value is evaluated to determine whether the data value satisfies a threshold or range for the particular data value."). Regarding Claim 9, Berger in view of Caithness teaches the method of claim 1, wherein the plurality of rules comprise a plurality of conditional statements (Berger, 13:55-61), and wherein the determining the one or more control insights corresponding to the entity further comprises: determining, based on the comparison of the plurality of indicators to the plurality of rules, the first subset of the plurality of indicators satisfying the at least one rule of the plurality of rules (Berger, 13:55-61); and deriving, based on the first subset of the plurality of indicators satisfying the at least one rule, at least one control insight of the one or more control insights (Berger, 4:64-5:19: scanned data regarding cybersecurity event data and vulnerabilities on the network is used to determine the status of cybersecurity controls (control insights)) that is mapped to the at least one rule (Berger, 18:55-19:7: specific cybersecurity factors of the framework that may need to be adjusted (control insights) have any adjustments made based on a corresponding rules-based analysis of the scan data to generate the specific adjustment (the insight is mapped to the rule(s))). Regarding Claim 10, Berger in view of Caithness teaches the method of claim 9, wherein the at least one rule is further defined by at least one threshold value, and further comprising: determining one or more values from the first subset of the plurality of indicators; comparing, based on the rule type of the at least one rule, the one or more values to the at least one threshold value; and determining, based on the comparison of the one or more values to the at least one threshold value, the plurality of indicators satisfies the rule (18:65-19:3, "In some embodiments, the rules-based analysis may be implemented as a series of rules, applied in a predetermined or dynamically determined sequence, in which a data value is evaluated to determine whether the data value satisfies a threshold or range for the particular data value.") to derive the at least one control insight (Berger, 4:64-5:19: scanned data regarding cybersecurity event data and vulnerabilities on the network is used to determine the status of cybersecurity controls (control insights). 18:55-19:7: specific cybersecurity factors of the framework that may need to be adjusted (control insights) have any adjustments made based on a corresponding rules-based analysis of the scan data to generate the specific adjustment (the insight is mapped to the rule(s))). Regarding Claim 13, and substantially Claim 22, Berger in view of Caithness teaches the method of claim 1, wherein the one or more control insights comprise two or more control insights, wherein the two or more control insights provide respective indications of the state of the same cybersecurity control mechanism, and determining, by an evaluation model and based on the two or more control insights, a perception of the same cybersecurity control mechanism (19:8-33: The results of a series of detection rules (the results being two or more control insights) provide insights into the firewall (respective indications of the state of the same cybersecurity control mechanism) and are individually used to applying adjustments to the overall score (perception) for the firewall control by the cybersecurity unit (interpreted as the evaluation model)) Regarding Claim 21, and substantially Claim 23, Berger in view of Caithness teaches the method of Claim 13, wherein the evaluation model determines the perception of the same cybersecurity control mechanism based on the respective positive, neutral, or negative assessment for each of the two or more control insights (Berger, 19:19-33: each answer (positive, neutral, or negative assessment) for the series of rules (each of the two or more control insights) is used to adjust the cybersecurity control factor score (perception of the same cybersecurity control mechanism)). Claim(s) 5, 11, and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Berger in view of Caithness as applied to claims 1 and 15 above, and further in view of Makovsky (US 20180302272 A1, cited in prior office action) Regarding Claim 5 and substantially claim 19, Berger in view of Caithness teaches the method of claim 1. Berger in view of Caithness does not teach but, in an analogous art, Makovsky teaches receiving a user input comprising a selection of a second subset of a plurality of indicators corresponding to at least one cybersecurity event of a plurality of cybersecurity events; and enriching the at least one cybersecurity event with the second subset of the plurality of indicators (Makovsky, [0031], "Implementations of this disclosure provide technological improvements particular to computer networks, for example, those concerning the generation of alerts based on events received from event sources monitoring the components of computer networks…. For example, implementations of this disclosure include graphical user interfaces for sequentially receiving user input used to identify attributes of particular components that will be associated with an alert and to enrich the alert using attributes of those components.", user input is received identifying attributes of particular components (a selection of a second subset of the plurality of indicators) and enriching an alert (cybersecurity event), which is part of a plurality of alerts/events). Makovsky is analogous with Berger in view of Caithness, as both inventions deal with enriching event data with contextual data related to the event data. One of ordinary skill in the art prior to the effective filing date of the claimed invention could further modify Berger in view of Caithness using Makovsky to receive a user input containing a selection of indicators with which to enrich event data by implementing the instructions taught by Makovsky into the invention of Berger in view of Caithness with predictable results. It would be obvious to one of ordinary skill in the art to do so because it facilitates the generation of alerts that include meaningful output (Makovsky, [0031], "Implementations of this disclosure can thus introduce new and efficient improvements in the ways in which events are processed for computer networks, such as by facilitating the generation of alerts including meaningful output for resolving issues occurring within the computer networks."). Regarding Claim 11, Berger in view of Caithness teaches the method of claim 1. Berger in view of Caithness does not teach but, in an analogous art, Makovsky teaches receiving a user input comprising a selection of the type and the first subset of the indicators for the at least one rule of the plurality of rules (Makovsky, [0031], "Implementations of this disclosure provide technological improvements particular to computer networks, for example, those concerning the generation of alerts based on events received from event sources monitoring the components of computer networks…. For example, implementations of this disclosure include graphical user interfaces for sequentially receiving user input used to identify attributes of particular components that will be associated with an alert and to enrich the alert using attributes of those components. The event rules are testable without generating false alert data for the computer network. When an event is later received from an event source, it is processed using the event rule by binding an alert generated therefor to the component identified in the event rule and enriching the alert using attributes of that component.", user input is received identifying attributes (a selection of the first subset of the indicators) of particular components (selection of the type), which is used for an event rule (the at least one rule of the plurality of rules)). Makovsky is analogous with Berger in view of Caithness, as both inventions deal with enriching event data with contextual data related to the event data. One of ordinary skill in the art prior to the effective filing date of the claimed invention could further modify Berger in view of Caithness using Makovsky to receive a user input of the selection of the type of event/rule and indicators for that event by implementing the instructions taught by Makovsky into the invention of Berger in view of Caithness with predictable results. It would be obvious to one of ordinary skill in the art to do so because it facilitates the generation of alerts that include meaningful output (Makovsky, [0031], "Implementations of this disclosure can thus introduce new and efficient improvements in the ways in which events are processed for computer networks, such as by facilitating the generation of alerts including meaningful output for resolving issues occurring within the computer networks."). Claim(s) 12 is/are rejected under 35 U.S.C. 103 as being unpatentable over Berger in view of Caithness as applied to claim 1 above, and further in view of Petersen (Petersen et al., US 20120131185 A1, cited in prior office action). Regarding Claim 12, Berger in view of Caithness teaches the method of claim 1, wherein each of the plurality of cybersecurity events comprises a respective timestamp indicative of a time at which the cybersecurity event was observed (15:7-8). Although Berger and Caithness each hint at using the timestamps of events to determine which events are important for the sake of analysis in relation to a time period (Berger, 15:25-31)(Caithness, [0091], [0111], [0118]), Berger in view of Caithness does not teach but, in an analogous art, Petersen teaches filtering, based on the timestamps of the plurality of cybersecurity events, the one or more event datasets by removing, from the one or more event datasets, a subset of the plurality of cybersecurity events comprising timestamps that are external to the first time period (Petersen, [0063], "Another filter may be a day/time filter 172 where a fact 124 must fall within any specified day of week and/or time of day filters (as determined by any appropriate time stamp associated with the fact 124)", [0074], "Furthermore, the filtering results 188 in the metadata 184 of the pending event 128' (see FIG. 3) may include various types of information such as the specific quantitative field(s) and threshold(s) observed or not observed, the specific value of the particular quantitative field reached upon or before generation of the pending event 128', the time limit or period within which the threshold was observed or not observed, time stamps, and/or the like."). Petersen is analogous with Berger in view of Caithness, as both inventions deal with timestamped cybersecurity events and corresponding time periods. One of ordinary skill in the art prior to the effective filing date of the claimed invention could further modify Berger in view of Caithness using Petersen to filter, based on the timestamps, the event datasets by removing, from the event datasets, a subset of the plurality of cybersecurity events comprising timestamps that are external to the first time period by implementing the instructions taught by Petersen into the invention of Berger in view of Caithness with predictable results. It would be obvious to one of ordinary skill in the art to do so because it allows for the system to determine which facts/events to further process and which ones to ignore (Petersen, [0062], "… to either subject the fact(s) 124 to further processing (e.g., as part of determining whether a "condition" of the RB 107 has been satisfied) or reject or otherwise ignore the fact(s) 124."), thus improving the efficiency within the system. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Garyani (GARYANI et al., US 20230107335 A1) teaches storing different customers' activity data for a specific time period ([0051]) and checking whether that shared activity is anomalous or not ([0052]), where the different customers are for a service provider ([0065]), where the events have defined types ([0097]), and further teaches displaying a text description of the indicator and recommendation for action ([0138]). O'Reilly (US 20180167414 A1) teaches determining whether a client computing system is in partial or complete compliance with a cybersecurity control using metadata on user behavior ([0029], [0073]), such as the NIST's framework ([0005]) and providing suggestions for improving the compliance for the control ([0006]), where the evaluation can be positive, negative, or neutral ([0040], [0051]) Crabtree (Crabtree et al., US 20210297452 A1) teaches passively monitoring endpoints on a network for user activity to locate anomalous behavior based on a threshold and providing security suggestions based on it ([0070]), using DNS and IP information as well as port scanning ([0050], [0059]) Cross (Cross et al., US 11720686 B1) teaches collecting data about interactions that a particular entity has on a network, such as IP traffic data, and analyzing the data along cybersecurity dimensions to determine weaknesses and recommend remediation actions (19:54-20:17), where the cybersecurity dimensions include cybersecurity controls (31:46-67) Kraus (KRAUS et al., US 20200057850 A1) teaches extracting insight instances from event data ([0241], [0242]) and creates a confidence score (perception of the system) from the one or more insight instances ([0259]). Any inquiry concerning this communication or earlier communications from the examiner should be directed to AMIR MAHDI HAJIABBASI whose telephone number is (703)756-5511. The examiner can normally be reached M-F 7:30-5 EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at (571) 270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /A.M.H./ Amir Mahdi HajiabbasiExaminer, Art Unit 2407 /Catherine Thiaw/Supervisory Patent Examiner, Art Unit 2407 9/9/2026
Read full office action

Prosecution Timeline

Jul 26, 2023
Application Filed
May 20, 2025
Non-Final Rejection mailed — §103
Nov 13, 2025
Response Filed
Dec 19, 2025
Final Rejection mailed — §103
Apr 20, 2026
Request for Continued Examination
Apr 29, 2026
Response after Non-Final Action
Sep 14, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705340
DETECTION OF MALICIOUS DIRECT MEMORY ACCESS DEVICE USED FOR DIRECT DEVICE ASSIGNMENT
2y 9m to grant Granted Aug 11, 2026
Patent 12682071
Software Security Defect Prediction Methods and Devices
2y 5m to grant Granted Jul 14, 2026
Patent 12682045
FAULT-ATTACK ANALYSIS DEVICE AND METHOD
2y 7m to grant Granted Jul 14, 2026
Patent 12670266
SECURE MULTI-PARTY COMPUTATION
2y 9m to grant Granted Jun 30, 2026
Patent 12664270
CONNECTED ASSET RISK MANAGEMENT
2y 3m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
87%
Grant Probability
93%
With Interview (+6.1%)
2y 7m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 31 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month