Pick a sub domain on the left to begin.
Work through the framework's control baselines, declare what applies to your entity, record each control as compliant, non compliant, or not applicable, and set a maturity level for each sub domain. The workbook does the framework's arithmetic: compliance percentages and maturity levels roll up from sub domain to domain to an overall score, with the rule that a sub domain cannot reach Baseline maturity until it is fully compliant. Everything stays in your browser.
This workbook encodes the assessment methodology described in the CBK CORF (dual layered compliance and maturity, with sub domain to domain to overall roll up). It is a working aid, not the official CBK toolkit and not a substitute for a CBK approved assessor. The control catalog is extracted from the published CORF v1.0 and should be validated against the source document before formal use.
Declare each domain and sub domain as Applicable or Not Applicable, with a justification where it does not apply. Anything marked Not Applicable is excluded from the scores. The CORF requires the SoA at the domain and sub domain level, not per individual control.
Pick a sub domain on the left to begin.
Scores across the applicable scope. Compliance is the share of applicable controls marked compliant; maturity is your assessed level, averaged up. Not applicable items are excluded.
Every control you marked Non compliant, within your applicable scope, is a gap. Prioritise it, assign an owner and a target date, and track it to closed. This is the remediation step of the CORF lifecycle, and it exports with the rest of your assessment.
Your assessment lives in this browser. Export it to a file to back it up, move it to another machine, or hand it to a colleague. Nothing is ever sent anywhere.
The export is a plain JSON file with your applicability choices, every control status and note, and your maturity levels and rationales. Import replaces the current work.