Framework-readiness cockpit
SandboxThe control-evidence register, read as audit-readiness. For each framework we count the controls that have a current, reviewed, in-window evidence artifact and divide by the controls in scope. The percentage is computed from real evidence presence — attach, review, or let an artifact go stale and it moves.
This is audit-readiness, not a certificate.
Coverage measures how much of each framework already has re-verifiable evidence behind it. It does not mean ControlFrame or the customer holds a SOC 2, HITRUST, ISO 27001, or FedRAMP certification — those are issued by an auditor or assessor after their own examination. What you get here is a coverage posture you can re-verify cryptographically. The final attestation stays the auditor's.
Computing coverage from the control-evidence register…