A module-native Cyber Assessment Framework — IGP rows, contributing-outcome judgements and evidence inheritance, assembled into a GovAssure-ready evidence pack.
Not a content pack bolted onto a US GRC tool — CAF v4 is first-class, with the IGP-level depth assessors actually expect.
All four objectives, 14 principles, IGP rows and contributing-outcome judgements built in.
Achieved / Partially / Not-achieved per contributing outcome, each with rationale and evidence.
Reuse evidence across principles and assessments — capture once, satisfy many.
Stage 1–4 evidence assembly with a CO-by-CO accept / concern / reject workflow.
Gaps become tracked actions with owners and dates — closure with an audit trail.
Baseline or Enhanced profile applied per system, scoping the assessment automatically.
Assemble a defensible CAF evidence pack continuously — not in a three-week scramble before the deadline.