Full Project Report
Where the project stands, in one document.
The Full Project Report is assembled server-side from governed project state and rendered as a document. It is layered deliberately: an executive can read the opening, an engineer can jump to the priorities, and an auditor can read all of it.
- Built from the same canonical state the product itself reads
- Layered for three different readers
- Issued as a version that stays what it was
What is in it
The sections the report actually produces.
This list follows the current generator rather than an idea of what such a report might contain. Where a project has not run a module, the report says so rather than leaving a gap that reads as a zero.
- Assessment coverage
- Which modules have been run, and therefore what the rest of the document can speak for.
- Where you stand
- The project's overall position across what has been assessed.
- Priority actions
- Prioritised findings, grouped by the time window in which they can realistically be addressed.
- Remediated since assessment
- Requirements whose current state has moved since the frozen baseline, kept separate from open work.
- Findings by domain
- The findings, organised by the part of the model they belong to.
- IEC 62443 status
- The assessed position across the foundational requirements, for the requirements in scope.
- OT maturity
- The OT domain maturity result, where that module has been completed.
- NIS2 Quick Scan
- The measure-by-measure position from the Quick Scan.
- NIS2 Full Readiness
- The readiness result, where the full assessment has been run.
- Zones & conduits
- The architecture context the findings above refer to.
- Not yet assessed
- What has not been looked at: stated explicitly, because an absence read as a pass is the most dangerous line in any report.
- Auditor notes and sign-off
- Space for the assessor's own notes, and the sign-off block.
Rendered
A document, not a payload.
The primary rendering is the readable one. The underlying data is what the product already holds; the report's job is to present it in an order somebody can follow.

What it does not claim.
The report describes readiness and records what was assessed. It is not a certification, not an audit opinion, and not a statement that the project is compliant with IEC 62443 or NIS2. Where the report shows a compliance posture percentage, that is a measure of assessed requirement status, not a claim that the project is that percentage compliant with a framework.
Related
Reports
The other report kinds, and how issuance works.
Findings & Evidence
Where the findings in the report come from.
Architecture
The zones and conduits the report refers to.
Read one end to end.
See a Full Project Report generated from a real project, and the version record behind it.