Coverage

See every gap,
months early.

Set each control to full, partial or none and devguard rolls it up into an overall coverage percentage and a per-framework breakdown. Open gaps show up control by control as you work, so you find them with months to fix them instead of in the two weeks before an audit.

Start for freeBook a conversation
Maps toISO/IEC 27001SOC 2GDPRNIST CSFPCI DSS
++++
app.devguard.ch / coverage
63 / 93 controls
Overall coverage
Overall coverage
68%
controls met
Met63
Partial14
Gap16
ISO 2700171%
SOC 264%
GDPR82%
By control domain
MetPartialGap
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO/IEC 27701
  • ISO 9001
  • ISO 14001
  • ISO 45001
  • Swiss nFADP
How it works

Set status, watch it roll up.

Coverage is the sum of where each control stands. You set the status; the percentages and the gaps follow.

01

Set each control’s status

Mark every control as full, partial or none, with anything untouched left as unknown. Each control carries its own status and a note describing the gap, so the state of a requirement is explicit, not implied.

02

Roll it up per framework

devguard counts your control statuses into an overall coverage percentage and a percentage per framework. ISO 27001, SOC 2 and GDPR each show how complete they are from the same control set, with full counts of covered, partial and uncovered controls.

03

Find gaps by control, early

Open gaps surface control by control as you go, not as a single number at the end. You see exactly which requirements are partial or uncovered while there’s still time to act on them.

Gaps in months, not weeks

Because every control’s status is live, an uncovered requirement is visible the day it falls behind, so the gap list arrives months before the audit instead of in the final fortnight.

Why it’s built this way

Built to surface gaps, not hide them.

Four choices behind how coverage works here, each one something you can check.

01

A status on every control

Each control is full, partial, none or unknown, so coverage is a count of real states rather than an estimate.

02

Per-framework, from one control set

Each framework shows its own coverage percentage drawn from the same controls, so adding a standard reuses what’s already mapped.

03

Gaps named at the control level

An uncovered or partial control shows up individually, with a note describing the gap, instead of hiding inside a single percentage.

04

Unknowns stay visible

Controls you haven’t assessed are flagged as unknown rather than counted as covered, so the percentage doesn’t flatter you.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours and exportable in full at any time, with no lock-in.

See the full feature comparison

One module of the platform

Where coverage connects.

Coverage is the roll-up of everything else. It reads from your controls, the policies that satisfy them, the audits that test them and the reports you share, all in the same workspace.

ISO 27001SOC 2GDPRNIST CSF

Frameworks & controls

Coverage rolls up the control set every framework shares.

policyv1.3
access_control {
require mfa = true
}

Policies

A published policy moves the controls it covers forward.

Internal audit00:42
Access controls
Backup & recovery
Incident response

Audits

Close the gaps coverage surfaces before the audit.

86%
Shared with
JDAKMR+3

Reports

Export coverage and gaps as a PDF to share.

FAQ

The questions evaluators ask.

What do “full, partial and none” mean?

They’re the status of each control. Full means the control is met, partial means it’s underway, and none means it’s a gap. Controls you haven’t assessed yet stay unknown, so they’re never silently counted as covered.

Does coverage break down per framework?

Yes. You get an overall coverage percentage and a separate percentage for each framework, drawn from the same control set, so ISO 27001, SOC 2 and GDPR each show how complete they are without you maintaining a separate tracker per standard.

Can I see exactly which controls are gaps?

Yes. Gaps show up control by control, each with a note describing what’s missing, rather than rolling into a single number. You can see precisely which requirements are partial or uncovered while there’s still time to fix them.

How is this different from a spreadsheet or another GRC tool?

A coverage spreadsheet is a snapshot someone updates by hand before the audit, so it’s only as current as the last person to touch it. Here, coverage is computed live from each control’s status, rolls up per framework, and surfaces gaps by control as they happen, so the picture is current the day you open it, not the week before the deadline.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. Your control statuses, coverage and gaps are yours and exportable at any time, so there’s no lock-in.

See where every framework stands, gap by gap.

Set each control’s status once and watch coverage roll up per framework, with open gaps surfaced by control months before the audit instead of the week before.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free