The UK NCSC Cyber Assessment Framework v4.0 is the framework UK regulators use to assess operators of essential services. XIRIQ presents it the way the CAF document does.
Objectives, principles, outcomes
The CAF has four objectives (A Managing security risk, B Protecting against cyber attack, C Detecting cyber security events, D Minimising the impact of incidents), split into 14 principles, split into 41 contributing outcomes. The contributing outcome is the unit you assess: each one is judged Achieved, Partially Achieved (where the CAF defines that level for it) or Not Achieved.
How status is judged
In Quick mode you set the level yourself. In Detailed mode XIRIQ derives it from the indicators: any true Not Achieved indicator forces Not Achieved regardless of everything else; Achieved needs every applicable Achieved indicator true; Partially Achieved (where the column exists) needs every applicable Partially Achieved indicator true. Anything else is left as assessor judgement required, never silently downgraded.
What IGPs are
Indicators of good practice are the CAF's evidence statements: concrete descriptions of what Not Achieved, Partially Achieved and Achieved look like for an outcome. They are indicators, not a checklist; the NCSC is explicit that assessment is a judgement informed by them. Detailed mode puts each indicator in front of you as a true/false/not-applicable question.
Why there is no CAF score
The CAF deliberately has no scoring scheme: adding up outcomes would let strength in one area mask a serious weakness in another. XIRIQ follows that. Results are presented as the distribution of judgements and, where a target profile is set, attainment against it. Where a percentage appears it is labelled indicative and never called a compliance score.