· intuitem · News  · 6 min read

What's New in CISO Assistant — Week 41, 2026 (v4.0.8 – v4.0.9)

v4.0.8 and v4.0.9 let you set a custom score scale on an audit without cloning its framework, bring the SCF 2026.3 framework and a proper ASD Essential Eight (November 2023) model, make every linked-object tab on applied controls able to link existing objects, load long autocomplete lists in batches, and fix a seat-count regression that made readers count as editors.

v4.0.8 and v4.0.9 let you set a custom score scale on an audit without cloning its framework, bring the SCF 2026.3 framework and a proper ASD Essential Eight (November 2023) model, make every linked-object tab on applied controls able to link existing objects, load long autocomplete lists in batches, and fix a seat-count regression that made readers count as editors.

This post covers two releases published on September 30: v4.0.8, which carries the changes, and v4.0.9, a security-only patch released an hour later. The headline is custom score scales on audits. There are also two framework updates, a more consistent applied-control page, faster autocomplete fields, and a licensing fix that administrators on v4.0.7 should read.

Custom Score Scales Without Cloning the Framework

Until now, an audit used the scoring scale of its framework. If your organisation scores on 1 to 4 and the framework scores on 0 to 100, the usual workaround was to clone the framework and edit its scale, then maintain the clone.

v4.0.8 moves the scale onto the audit (PR #4915):

  • Presets or a custom range — pick one of the standard presets (0–100, 0–5, 1–5, 1–4, 0–3) or define your own minimum and maximum. Each score level can have a name and a description, with translations, and they are shown in the user’s language with a fallback when a translation is missing.
  • Organisation defaults — General Settings has a default scale, and eligible new audits start with it.
  • The framework still has the last word — when a framework defines its own scale, it limits the options you get.
  • Changing the range on a scored audit — you can change the scale of an audit that already has scores. CISO Assistant lists the scores that will be affected and, once you confirm, converts them proportionally to the new range. Nothing is converted silently.

The scale is kept in domain export and import, and the mapping engine accounts for it. Thanks to @ab-smith.

Framework & Library Updates

  • SCF 2026.3 — the Secure Controls Framework moves to release 2026.3, with a mapping from SCF 2025.2.2 so existing work can be carried over. The library is generated by a new conversion script that turns the official SCF workbook into a CISO Assistant library. Deprecated controls are kept but marked non-assessable (PR #4921).
  • ASD Essential Eight, November 2023 — a new implementation of the Essential Eight Maturity Model, with its three maturity levels and assessable requirements across the eight mitigation strategies. The existing library is relabelled as the legacy model and points to its successor, and a transition mapping links the two, so audits on the old model can be moved to the new one (PR #4937).

Both thanks to @ab-smith.

The tabs at the bottom of an applied control were inconsistent. Evidence and Tasks had both a create and a select existing button. Documents could only create. Findings, Assets and Incidents had no button at all, so users concluded the link was impossible. In fact it was possible, but only from a collapsed section of another form.

All of these tabs now have both buttons (PR #4826). Creating an object from a tab links it to the control automatically. For documents, the fix also closes a silent failure: the API answered 200 to a request to link an existing document but did not create the link. Thanks to @Claquetteuuuh.

Faster Fields and a Wider Asset Board

  • Autocomplete loads in batches — selection fields such as those on requirement assessments and risk scenarios no longer fetch every option up front. Results arrive in batches, a count shows when more exist, and a hint suggests scrolling or refining the search. Results also show more context, such as category, folder or assessment, so two items with the same name can be told apart (PR #4920).
  • Assets from other domains on the asset board — the experimental asset board shows linked assets that live in other folders, with markers on cross-folder links and placeholders for assets you are not allowed to see. You can search for assets in other folders and pin them to the board. The board can arrange itself, and it remembers pinned assets between visits. Link changes and batch creation check folder permissions (PR #4919).
  • A faster current-user endpoint — the endpoint that returns the signed-in user and their folder permissions computes those permissions more efficiently (PR #4945, thanks to @monsieurswag), and the Enterprise layout now loads the same way as Community (PR #4946).

Thanks to @ab-smith unless noted.

Licensing: Readers No Longer Count as Editors

If you upgraded to v4.0.7, check your seat count. The notification centre introduced in v4.0.7 gave every reader permission to edit and delete their notifications. Seat counting treats any edit or delete permission as editor access, so readers started to be counted as editors. v4.0.8 removes those permissions from the baseline reader role (readers can still see their notifications) and excludes notification permissions from the editor check (PR #4947). Thanks to @ab-smith.

Security

v4.0.9 updates PyJWT to fix CVE-2026-102268, rated critical. The maintainers state that the vulnerability cannot be exploited in CISO Assistant’s setup, but they shipped the fix so the container images carry no critical finding. SSO was tested manually after the update (PR #4952). Thanks to @eric-intuitem.

Bug Fixes

  • Delete previews tell the truth about TPRM audits — deleting an entity assessment said its audit would not be deleted, then deleted it. The preview now lists the audit as deleted, and handles audits in enclave folders correctly: an empty enclave folder is removed with its last audit, and sibling audits are kept. Batch deletion behaves the same way (PR #4818). Thanks to @Axxiar.
  • Cmd/Ctrl+click opens a new tab, and only that — in list views, a modified click on a row or on the view and edit icons opened the page in a new tab and navigated the current one. Modified clicks now follow the browser’s normal behaviour, which matters on a Mac trackpad, where there is no middle click (PR #4943). Thanks to @Spaghetto784.
  • Year filter on evidence revisions — the revisions list had a Labels filter that did nothing, because revisions have no labels. It is replaced with a Year filter on the creation date (PR #4925). Thanks to @Spaghetto784.
  • Breadcrumbs after creating an object — after creating an audit and switching to table or flash mode, the audit’s name was missing from the breadcrumbs, so there was no way back to it (PR #4924). Thanks to @martinzerty.
  • The N+1 benchmark cleans up after itself — the benchmark command added in v4.0.3 now rolls back its temporary data when a run succeeds, and supports runs with a single object (PR #4780). Thanks to @monsieurswag.

For full details, see the v4.0.8 and v4.0.9 release notes on GitHub.

Back to Blog

Related Posts

View All Posts »
What's New in CISO Assistant — Week 40, 2026 (v4.0.7)

What's New in CISO Assistant — Week 40, 2026 (v4.0.7)

v4.0.7 brings an in-app notification centre, a risk trajectory view that plays a risk assessment forward in time, X-rays that cover governance and operations and point at active controls with no evidence behind them, per-user module visibility, Mermaid diagrams in documents and PDFs, and workflows that can draft and review documents.

What's New in CISO Assistant — Week 39, 2026 (v4.0.5 – v4.0.6)

What's New in CISO Assistant — Week 39, 2026 (v4.0.5 – v4.0.6)

v4.0.5 lands a mapping table beside the graph, relation graphs on detail pages, a command palette that can now search and create, workflow steps that record measurements and file scan results — and a Power BI connector release that anyone who upgraded to 4.0 needs to install. v4.0.6 follows with an evidence-upload fix worth taking straight away.

What's New in CISO Assistant — Week 38, 2026 (v4.0.4)

What's New in CISO Assistant — Week 38, 2026 (v4.0.4)

A single patch after the busy 4.0.2/4.0.3 pair — but it carries a real behaviour change for dynamic frameworks, honest loading states on list views, and a container-hardening step that operators need to read before upgrading.

What's New in CISO Assistant — Week 37, 2026 (v4.0.2 – v4.0.3)

What's New in CISO Assistant — Week 37, 2026 (v4.0.2 – v4.0.3)

The first two patches after 4.0 are anything but quiet: quick forms turn ad-hoc requests into a real intake channel, every PDF export moves onto one engine, the audit table-mode is rebuilt, workflows gain AI steps, and a focused performance push targets the pages that were slowest to load.