· intuitem · News  · 8 min read

What's New in CISO Assistant — Week 43, 2026 (v4.1.1)

v4.1.1 adds vendor tiering backed by scored criticality forms, outcome rules on frameworks that check the CyFun 2025 conformity criteria, an export to the official CCB CyFun tools, paginated external APIs and bulk writes in workflows, an experimental domain compliance tree, more MCP coverage (advanced EBIOS RM, assets, teams), and new libraries: China PIPL, OWASP SAMM v2.2, ISO 27001 ↔ HDS and IEC 62443 ↔ ANSSI mappings.

v4.1.1 adds vendor tiering backed by scored criticality forms, outcome rules on frameworks that check the CyFun 2025 conformity criteria, an export to the official CCB CyFun tools, paginated external APIs and bulk writes in workflows, an experimental domain compliance tree, more MCP coverage (advanced EBIOS RM, assets, teams), and new libraries: China PIPL, OWASP SAMM v2.2, ISO 27001 ↔ HDS and IEC 62443 ↔ ANSSI mappings.

This post covers v4.1.1, published on October 9. It is labelled a patch, but it is a large one. Third-party risk management gets vendor tiering. Framework outcome rules can now compute scores and check conformity criteria, and CyFun 2025 is the first framework to use them. Workflows can page through external APIs and write objects in bulk. There is no breaking change in this release.

Vendor Tiering (TPRM)

Vendors could be assessed, but not ranked. v4.1.1 adds an org-wide tier scale and a way to set a vendor’s tier from a scored questionnaire (PR #4973).

  • Tier scale — an ordered scale, by default critical, high, medium and low, edited from Third parties → Tier scale by administrators and domain managers of Global. Tiers can be renamed, recoloured, reordered and hidden. Built-in tiers cannot be deleted.
  • Tier on vendors — the entity page and table show the tier, its source (manual, assessment or override), its date and its score. You can set it from the edit form, with a batch action or with a right-click on Change tier, and filter entities by tier, including those with no tier.
  • Criticality forms — quick forms can now score pages (sum, max or average) and compute values with number rules. A form can name its subject, such as the vendor being assessed, and a publication can set the vendor’s tier when a response is accepted, from score bands, outcome floors or both. The highest result wins.
  • Assessment flow — Assess tier on the vendor page starts a response about that vendor. The projected tier can be shown while the form is filled in. A self-assessment applies the tier on submit when the submitter can edit the vendor, otherwise it goes to review. A publication can also always require review. The reviewer sees what accepting will write and can override it with a justification.
  • Starter library — a bilingual Vendor tiering form (business impact and data exposure) comes with a suggested tier setup that is pre-filled when you publish it.
  • Library builder — quick forms can be published from their page, number rules can use a page’s score, tier bands are pre-filled from the scale, and Ctrl/Cmd+S saves. URNs are no longer re-minted on every save.

Thanks to @ab-smith.

Outcome Rules on Frameworks, and CyFun 2025

The CEL rules that quick forms use can now run on frameworks too (PR #5012).

  • Number rules compute a value that other rules can read. Labelled ones are shown on the audit page next to the outcomes.
  • Rules run in order, so a yes/no rule can build on the rules above it, for example “criteria met” when every criterion above is met. Quick forms follow the same order now.
  • Rules can be limited to implementation groups, and they apply to audits whose scope includes one of those groups.
  • Rules can read scores — the audit’s implementation, documentation and maturity scores and its target; each requirement’s documentation and maturity scores and groups; and per-section and per-group scores, computed with the audit’s calculation method.
  • Outcomes are refreshed when scores, scope or scoring settings change, or when a library update changes the rules. A rule that names an unknown requirement, section or group refuses the library load.

CyFun 2025 audits use these rules to show the CCB conformity criteria for their level: total maturity (2.5 for BASIC, 3 for IMPORTANT, 3.5 for ESSENTIAL), every key measure, every category at 3 or more for ESSENTIAL, and the exclusion limits. Each audit then gets an overall “CCB conformity criteria met” result. Labels are in English, French and Dutch.

PR #4994 aligns CyFun scoring with the CCB’s own tools:

  • Scores are rounded once, at the end, to two decimals. Maturity used to be truncated three times.
  • CyFun 2023 and 2025 audits default to Average of averages, and CyFun 2025 counts N/A at the level’s target. The 1–5 scale is locked, and an unset documentation score counts as the scale minimum, not 0. These defaults are declared by the framework. Existing audits are not changed.
  • Export to the official CCB tool — CyFun 2023 audits export to the CCB CyFun 2023 workbook, and CyFun 2025 audits export to the BASIC, IMPORTANT or ESSENTIAL workbook based on their implementation groups. The workbook’s charts and dropdowns are kept.
  • The CyFun 2025 library is aligned with the 2026 CCB booklets in English, Dutch and French, and the CyFun 2023 → 2025 mapping follows the CCB transposition table.
  • A new setting, Show the documentation score first, applies wherever both scores are shown.

Thanks to @ab-smith.

Workflows: Paginated APIs and Bulk Writes

Workflows that pull data from security tools now handle the volumes those tools return (PR #5027).

  • HTTP requests support OAuth client-credentials authentication and pagination, with safeguards on the number of pages and a pagination status in the output.
  • A bulk action creates or updates objects from a list, with a configurable item limit and errors handled per item.
  • Run lists show output previews, and output size limits can be configured.
  • New templates — Microsoft Entra ID identity metrics, Microsoft Defender device inventory and SentinelOne coverage.

Thanks to @ab-smith.

MCP: Advanced EBIOS RM, Assets and Teams

  • Advanced EBIOS RM — the MCP server catches up with v4.1.0: study likelihood methods, the study frame, operating-mode likelihood, kill-chain steps with techniques, success probability, difficulty and supporting assets, and target-objective categories on RO/TO couples (PR #5007). Thanks to @ab-smith.
  • Assets — update_asset no longer resets security objectives it was not asked to change. Asset tools now cover all security criteria, capabilities and recovery objectives, and durations can be written as 2h or 1h30m. A new get_asset_security_gaps tool compares objectives with capabilities. Entities gain relationship and address (PR #4981). Thanks to @JohnGanem.
  • Teams — new tools list, create and update teams, including leader, deputies and members, so risk owners can be managed as teams. Users can be given by name, ID or email (PR #4983). Thanks to @jledoze.

Audits, Documents and Import

  • Exclude N/A from the tree — a toggle on the audit page and in table mode removes not-applicable requirements from the percentages (PR #4853). Thanks to @monsieurswag.
  • Global evidences in the audit’s evidence list — evidence attached to the audit itself now appears there, along with evidence linked through applied controls and task templates (PR #4845). Thanks to @Axxiar.
  • Pending document revisions — a v2 still in review used to be invisible while v1 was in force. The documents list now shows it as a badge, and the document header shows both revisions (PR #4817). Thanks to @Claquetteuuuh.
  • Domains in the data wizard — domains can be imported and exported with their filtering labels and IAM-group setting, and an export re-imports as is. Each imported row is now written in its own transaction (PR #5006). Thanks to @Spaghetto784.
  • Threats in risk imports — a threats column links imported risk scenarios to threats by ref_id or name (PR #5017). Thanks to @martinzerty.
  • Findings exports — recommendation and priority are now included in the Markdown, PDF and XLSX exports (PR #5001). Welcome to @theluckystrike, who makes their first contribution with this fix.
  • Domain compliance tree (experimental) — a new view of audit results across domains, by compliance or score, with filters for implementation group, section and campaign, and a shortcut to the weakest audited areas (PR #5029). Thanks to @ab-smith.

Framework & Library Updates

  • China PIPL — the Personal Information Protection Law, with its compliance audit measures, plus Chinese labels for more of the interface (PR #5024).
  • OWASP SAMM v2.2 — the Software Assurance Maturity Model, with maturity scoring by function and practice and target levels (PR #5031).
  • ISO/IEC 27001:2022 ↔ HDS v2.0 — mappings in both directions, with annotated HDS requirements (PR #5000).
  • IEC 62443 ↔ ANSSI — mappings between the ANSSI detailed measures guide for industrial systems (v2) and six parts of IEC 62443 (PR #5028).

Thanks to @ab-smith.

Security

  • Score visibility on inherited results — when field visibility hid an audit’s scores from a role, the inheritance overlay in the framework report and combined tree still carried them, so “Apply domain inheritance” showed them anyway. The overlay is now redacted with the same rules, including values coming from ancestor audits (PR #4899). Thanks to @nas-tabchiche.
  • Risk acceptance approvers must now be able to approve both in the acceptance’s domain and in the domain of every linked scenario (PR #5020).
  • CRQ budget overview now respects the user’s permissions and no longer exposes hidden control owners (PR #5019).

Bug Fixes

  • Scores saved without user input — on the auditee page, opening an unscored requirement saved it as 0 and marked it scored. Scores are now saved only when you move the slider (PR #5002).
  • Deselected EBIOS RM operational scenarios were still copied into the synced risk assessment through their attack path (PR #4958).
  • Risk assessment import left every impact and probability unrated when the matrix came from the library builder. Labels now match level positions, and unknown values raise a warning instead of erasing the rating (PR #4987).
  • Library import/export now carries visibility expressions, importance, target, min and max scores, and score definitions (PR #5022). Thanks to @eric-intuitem.
  • ServiceNow — the table picker shows scoped app tables such as sn_customerservice_case, and both pickers keep paging past pages that ACLs shortened (PRs #4993, #4998). Existing integrations need a schema refresh in the field mapper. Thanks to @nas-tabchiche.
  • Embedded table filters are now remembered per page (PR #4630), and the evidence attachment hash is shown and backfilled for older revisions (PR #4785).
  • Smaller fixes: risk-level filter labels across several matrices, multi-value domain and perimeter filters on risk scenarios, the “current view” export including the search, tooltips in dark mode, library quick filters, and the CSV/XLSX format on public snapshot exports (PRs #5020, #4990, #4982).

Thanks to @Spaghetto784 and @martinzerty for many of these fixes.

Localisation

  • Polish — the Polish localisation is updated (PR #4968). Welcome to @amrutadotorg, who makes their first contribution with this update.

For full details, see the v4.1.1 release notes on GitHub.

Back to Blog

Related Posts

View All Posts »
What's New in CISO Assistant — Week 42, 2026 (v4.1.0)

What's New in CISO Assistant — Week 42, 2026 (v4.1.0)

v4.1.0 brings a large rework of the EBIOS RM module (study framing, RO/TO radar, standard and advanced likelihood methods on kill-chain steps), arithmetic in workflows with a CEL compute action, MCP write tools for a full risk review, a delegated user-creator role, entity-assessment exports, the BSI C5:2026 framework, German email templates, and a breaking change to the current-user API.

What's New in CISO Assistant — Week 41, 2026 (v4.0.8 – v4.0.9)

What's New in CISO Assistant — Week 41, 2026 (v4.0.8 – v4.0.9)

v4.0.8 and v4.0.9 let you set a custom score scale on an audit without cloning its framework, bring the SCF 2026.3 framework and a proper ASD Essential Eight (November 2023) model, make every linked-object tab on applied controls able to link existing objects, load long autocomplete lists in batches, and fix a seat-count regression that made readers count as editors.

What's New in CISO Assistant — Week 40, 2026 (v4.0.7)

What's New in CISO Assistant — Week 40, 2026 (v4.0.7)

v4.0.7 brings an in-app notification centre, a risk trajectory view that plays a risk assessment forward in time, X-rays that cover governance and operations and point at active controls with no evidence behind them, per-user module visibility, Mermaid diagrams in documents and PDFs, and workflows that can draft and review documents.

What's New in CISO Assistant — Week 39, 2026 (v4.0.5 – v4.0.6)

What's New in CISO Assistant — Week 39, 2026 (v4.0.5 – v4.0.6)

v4.0.5 lands a mapping table beside the graph, relation graphs on detail pages, a command palette that can now search and create, workflow steps that record measurements and file scan results — and a Power BI connector release that anyone who upgraded to 4.0 needs to install. v4.0.6 follows with an evidence-upload fix worth taking straight away.