f8de5a6dff
Per the Co-Pilot-calm principle: the findings table stays compact (Befund / CRA-Anforderung / Risiko / Maßnahmen) and the NIST/OWASP + ISO 27001 best-practice depth is revealed per finding via a "NIST/OWASP" toggle. Keeps the 3-layer model (CRA obligation -> measure -> best-practice depth) tidy. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>