Framework-readiness cockpit

Sandbox

The control-evidence register, read as audit-readiness. For each framework we count the controls that have a current, reviewed, in-window evidence artifact and divide by the controls in scope. The percentage is computed from real evidence presence — attach, review, or let an artifact go stale and it moves.

This is audit-readiness, not a certificate.

Coverage measures how much of each framework already has re-verifiable evidence behind it. It does not mean ControlFrame or the customer holds a SOC 2, HITRUST, ISO 27001, or FedRAMP certification — those are issued by an auditor or assessor after their own examination. What you get here is a coverage posture you can re-verify cryptographically. The final attestation stays the auditor's.

Computing coverage from the control-evidence register…

Framework-Readiness Cockpit | ControlFrame