A module-native Cyber Assessment Framework - IGP rows, contributing-outcome judgements and evidence inheritance, assembled into a GovAssure-ready evidence pack.
Not a content pack bolted onto a US GRC tool - CAF v3.2 is first-class, with the IGP-level depth assessors actually expect.
All four objectives, 14 principles, IGP rows and contributing-outcome judgements built in.
Achieved / Partially / Not-achieved per contributing outcome, each with rationale and evidence.
Reuse evidence across principles and assessments - capture once, satisfy many.
Stage 1-4 evidence assembly with a CO-by-CO accept / concern / reject workflow.
Gaps become tracked actions with owners and dates - closure with an audit trail.
Baseline or Enhanced profile applied per system, scoping the assessment automatically.
| Capability | E2E Risk | Spreadsheet tracker | Generic US GRC tool |
|---|---|---|---|
| NCSC CAF v3.2 content | Native - all 14 principles | Manually transcribed | US control set, mapped loosely |
| IGP-level depth | Indicators of Good Practice built in | Free-text cells | Generic maturity levels |
| Contributing-outcome judgements | Achieved / Partial / Not, with rationale | Colour-coded cells | Pass/fail scoring |
| Evidence inheritance | Capture once, satisfy many outcomes | Re-attached every time | Per-control upload |
| GovAssure pack | Stage 1-4 assembled for you | Hand-built each round | Export to PDF only |
| Profile-aware scoping | Baseline / Enhanced per system | Not supported | Not CAF-aware |
Objective-by-objective status with rationale and evidence per contributing outcome.
Stage 1-4 assembly with an accept / concern / reject workflow for assessors.
Every gap as a tracked action with an owner, a due date and a closure trail.
Assemble a defensible CAF evidence pack continuously - not in a three-week scramble before the deadline.