Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 24 additions & 22 deletions docs/FRAMEWORK-COVERAGE.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

> **Auto-generated.** Regenerated by `node plugins/grc-engineer/scripts/generate-coverage.js`. Do not hand-edit — your changes will be overwritten on the next release.

Last generated: 2026-04-18
Last generated: 2026-07-19

This page tracks which of the 249 frameworks in the [Secure Controls Framework](https://securecontrolsframework.com) crosswalk have a dedicated plugin in this repo. Frameworks without a dedicated plugin are **already usable today** via `/grc-engineer:gap-assessment <scf-framework-id>` through the SCF crosswalk.

Expand All @@ -11,39 +11,52 @@ This page tracks which of the 249 frameworks in the [Secure Controls Framework](
| | |
|---|---|
| Total SCF-mapped frameworks | 249 |
| With dedicated plugin | **15** (6.0%) |
| Crosswalk-only (no plugin yet) | 234 |
| With dedicated plugin | **28** (11.2%) |
| Crosswalk-only (no plugin yet) | 221 |
| Shipped plugins without SCF mapping | 6 |

### By depth

| Depth | Count | Description |
|---|---|---|
| Full | 0 | Framework-native workflow commands + Reference content |
| Reference | 15 | Scope + evidence checklist + framework-specific SKILL |
| Stub | 0 | Scaffolded delegation to `/grc-engineer:gap-assessment` |
| Reference | 26 | Scope + evidence checklist + framework-specific SKILL |
| Stub | 2 | Scaffolded delegation to `/grc-engineer:gap-assessment` |

See [Framework Plugin Guide](FRAMEWORK-PLUGIN-GUIDE.md) for depth definitions and level-up checklists.

## Shipped plugins

| Namespace | Depth | SCF framework ID | Display name |
|---|---|---|---|
| `/au-apra-cps-234:` | reference | `apac-aus-ps-cps-234-2019` | Australia - Prudential Standard CPS 234 (2019) |
| `/ch-fadp:` | stub | `emea-che-fadp-2025` | Switzerland - FADP |
| `/cis-controls:` | reference | `general-cis-csc-8-1` | Critical Security Controls (CSC) (v8.1) |
| `/cmmc:` | reference | `usa-federal-dow-cmmc-2-level-2` | Cybersecurity Maturity Model Certification (CMMC) 2.0 - Level 2 |
| `/csa-ccm:` | reference | `general-csa-cmm-4-1-0` | Cloud Controls Matrix (CCM) (v4.1.0) |
| `/cyber-essentials-plus:` | reference | `emea-gbr-ce-2021` | UK NCSC Cyber Essentials Plus (CE+) v3.3 Danzell |
| `/dora:` | reference | `emea-eu-dora-2023` | EU Digital Operational Resilience Act (DORA) (2023) |
| `/essential8:` | reference | `apac-aus-essential-8-2024` | Australia - Essential Eight (2024) |
| `/eu-nis2:` | reference | `emea-eu-nis2-2022` | EU NIS2 Directive (2022) |
| `/fedramp-rev5:` | reference | `usa-federal-gsa-fedramp-5-mod` | FedRAMP R5 - Moderate Baseline |
| `/gdpr:` | reference | `emea-eu-gdpr-2016` | EU General Data Protection Regulation (GDPR) (2016) |
| `/glba:` | reference | `usa-federal-law-glba-cfr-314-2023` | Gramm Leach Bliley Act (GLBA) (2023) |
| `/ind-dpdpa:` | reference | `apac-ind-dpdpa-2023` | India - DPDPA (2023) |
| `/ismap:` | reference | `apac-jpn-ismap` | Japan - Information System Security Management and Assessment Program (ISMAP) |
| `/iso27001:` | reference | `general-iso-27001-2022` | ISO 27001 (2022) |
| `/jp-appi:` | reference | `apac-jpn-ppi-2020` | Japan - Act on the Protection of Personal Information (2020) |
| `/nist-800-53:` | reference | `general-nist-800-53-r5-2` | NIST SP 800-53 R5 |
| `/nist-csf-20:` | reference | `general-nist-csf-2-0` | NIST Cybersecurity Framework (v2.0) |
| `/nydfs:` | reference | `usa-state-ny-dfs-23-nycrr500-2023-amd2` | New York Department of Financial Services 23NYCRR Part 500 (2023 Amendment 2) |
| `/pci-dss:` | reference | `general-pci-dss-4-0-1` | Payment Card Industry Data Security Standard (PCI DSS) (v4.01) |
| `/sg-mas-trm:` | reference | `apac-sgp-mas-trm-2021` | Singapore - Monitory Authority of Singapore (MAS) Technology Risk Management (TRM) Guidelines (2021) |
| `/singapore-pdpa:` | reference | `apac-sgp-pdpa-2012` | Singapore - Personal Data Protection Ac (PDPA) (2012) |
| `/soc2:` | reference | `general-aicpa-tsc-2017` | Trust Services Criteria (TSC) (2017) |
| `/us-ccpa:` | reference | `usa-state-ca-ccpa-cpra-2026` | California Consumer Privacy Act (CCPA) (2026) |
| `/us-finra:` | stub | `usa-federal-sro-finra` | FINRA Cybersecurity Rules |
| `/us-hipaa-security:` | reference | `US-HIPAA-Security` | US HIPAA Security Rule (45 CFR Part 164, Subpart C) |
| `/us-nerc-cip:` | reference | `usa-federal-nerc-cip-2024` | NERC Critical Infrastructure Protection (CIP) (2024) |
| `/us-sox:` | reference | `usa-federal-law-sox-2002` | SOX (2002) |

### Shipped without SCF mapping

Expand All @@ -60,7 +73,7 @@ These plugins exist in the marketplace but do not have a `framework_metadata.scf

## Not started

234 frameworks are supported today via the SCF crosswalk but have no dedicated plugin. To adopt one:
221 frameworks are supported today via the SCF crosswalk but have no dedicated plugin. To adopt one:

```bash
node plugins/grc-engineer/scripts/scaffold-framework.js <scf-framework-id>
Expand All @@ -72,7 +85,7 @@ Or keep using the crosswalk directly:
/grc-engineer:gap-assessment "<scf-framework-id>"
```

### Americas — 73 frameworks
### Americas — 70 frameworks

<details><summary>Expand</summary>

Expand All @@ -83,11 +96,11 @@ Or keep using the crosswalk directly:
| `americas-bhs-dpa-2003` | Bahamas - DPA (2003) | 18 → 5 |
| `americas-bmu-mba-coc-2020` | Bermuda - Bermuda Monetary Authority Code of Conduct (2020) | 61 → 37 |
| `americas-bra-lgpd-2018` | Brazil - General Data Protection Law (LGPD) (2018) | 33 → 55 |
| `usa-state-ca-ccpa-cpra-2026` | California Consumer Privacy Act (CCPA) (2026) | 258 → 623 |
| `usa-state-ca-sb1386-2002` | California SB1386 (2002) | 4 → 6 |
| `usa-state-ca-sb327-2018` | California SB327 (2018) | 3 → 7 |
| `americas-can-itsp-10-171-2025` | Canada - ITSP.10.171 (2025) | 407 → 275 |
| `americas-can-osfi-b13-2022` | Canada - OSFI B-13 (2022) | 150 → 77 |
| `amaericas-can-osfi-self-assessment` | Canada - OSFI Cyber Security Self-Assessment Guidance | 141 → 88 |
| `americas-can-pipeda-2000` | Canada - Personal Information Protection and Electronic Documents Act (PIPEDA) (2000) | 28 → 17 |
| `usa-federal-dow-cert-rmm-1-2` | CERT-RMM (v1.2) | 85 → 753 |
| `usa-federal-law-coppa-2024` | Children's Online Privacy Protection Act (COPPA) (2024) | 10 → 8 |
Expand Down Expand Up @@ -117,7 +130,6 @@ Or keep using the crosswalk directly:
| `usa-federal-gsa-fedramp-5-high` | FedRAMP R5 - High Baseline | 561 → 490 |
| `usa-federal-gsa-fedramp-5-li-saas` | FedRAMP R5 - Li-SAAS Baseline | 383 → 269 |
| `usa-federal-gsa-fedramp-5-low` | FedRAMP R5 - Low Baseline | 383 → 269 |
| `usa-federal-sro-finra` | FINRA Cybersecurity Rules | 17 → 39 |
| `usa-federal-fda-21-cfr-part-11-2025` | Food & Drug Administration (FDA) 21 CFR Part 11 (2025) | 62 → 28 |
| `usa-federal-hhs-45-cfr-155-260-2016` | HHS § 155.260 (2016) | 36 → 44 |
| `usa-federal-law-hipaa-simplification-2013` | HIPAA Administrative Simplification (2013) | 170 → 576 |
Expand All @@ -130,15 +142,13 @@ Or keep using the crosswalk directly:
| `usa-state-ma-201-cmr-17-2008` | Massachusetts 201 CMR 17.00 (2008) | 53 → 37 |
| `americas-mex-fdpa-2010` | Mexico - Federal Law on Protection of Personal Data held by Private Parties (2010) | 23 → 25 |
| `usa-federal-nispom-2020` | National Industrial Security Program Operating Manual (NISPOM) (2020) | 35 → 226 |
| `usa-federal-nerc-cip-2024` | NERC Critical Infrastructure Protection (CIP) (2024) | 122 → 204 |
| `usa-state-nv-regulation-5-2024` | Nevada Operation of Gaming Establishment (NOGE) Regulation 5.260 (2024) | 20 → 11 |
| `usa-state-nv-sb220-2019` | Nevada SB220 (2019) | 3 → 4 |
| `usa-state-ny-shield-act-2019` | New York SHIELD Act (SB S5575B) (2019) | 28 → 45 |
| `usa-state-or-ors-646a-2025` | Oregon Consumer Information Protection Act (ORS 646A) (2025) | 24 → 97 |
| `usa-state-or-cpa-2023` | Oregon Consumer Privacy Act (SB 619) (2023) | 34 → 75 |
| `usa-federal-dow-safeguarding-nnpi-2010` | Safeguarding of NNPI (2010) | 32 → 68 |
| `usa-federal-sec-cybersecurity-rule-2023` | SEC Cybersecurity Rule (2023) | 40 → 15 |
| `usa-federal-law-sox-2002` | SOX (2002) | 4 → 17 |
| `usa-state-tn-tipa-2025` | Tennessee Information Protection Act (TIPA) (2025) | 29 → 76 |
| `usa-state-tx-cdpa-2025` | Texas Consumer Data Protection Act (2025) | 28 → 89 |
| `usa-state-tx-dir-security-control-standards-catalog-2-2` | Texas DIR Security Control Standards Catalog (v2.2) | 238 → 228 |
Expand All @@ -154,7 +164,7 @@ Or keep using the crosswalk directly:

</details>

### APAC — 26 frameworks
### APAC — 22 frameworks

<details><summary>Expand</summary>

Expand All @@ -165,16 +175,13 @@ Or keep using the crosswalk directly:
| `apac-aus-privacy-act-1998` | Australia - Privacy Act of 1998 | 23 → 12 |
| `apac-aus-privacy-principles-2026` | Australia - Privacy Principles (2026) | 26 → 13 |
| `apac-aus-ps-cps-230-2023` | Australia - Prudential Standard CPS 230 (2023) | 41 → 98 |
| `apac-aus-ps-cps-234-2019` | Australia - Prudential Standard CPS 234 (2019) | 52 → 38 |
| `apac-chn-cybersecurity-law-2017` | China - Cybersecurity Law (2017) | 27 → 34 |
| `apac-chn-data-security-law-2021` | China - Data Security Law (2021) | 15 → 24 |
| `apac-chn-csnip-2012` | China - Decision on Strengthening Network Information Protection (2012) | 10 → 4 |
| `apac-chn-pipl-2021` | China - Personal Information Protection Law (2021) | 79 → 100 |
| `apac-hkg-pdo-2022` | Hong Kong - Personal Data Ordinance (2022) | 14 → 14 |
| `apac-ind-dpdpa-2023` | India - DPDPA (2023) | 41 → 96 |
| `apac-ind-privacy-rules-2011` | India - Privacy Rules (2011) | 12 → 5 |
| `apac-ind-sebi-2024` | India - SEBI CSCRF (2024) | 170 → 129 |
| `apac-jpn-ppi-2020` | Japan - Act on the Protection of Personal Information (2020) | 58 → 134 |
| `apac-mys-pdpa-2010` | Malaysia - Personal Data Protection Act (PDPA) (2010) | 25 → 12 |
| `apac-nzl-hisf-suppliers-2023` | New Zealand - HISF Guidance for Suppliers (2023) | 101 → 68 |
| `apac-nzl-hisf-microsmall-2023` | New Zealand - HISF MicroSmall (2023) | 32 → 21 |
Expand All @@ -183,13 +190,12 @@ Or keep using the crosswalk directly:
| `apac-nzl-privacy-act-2020` | New Zealand - Privacy Act (2020) | 20 → 121 |
| `apac-phl-dpa-2012` | Philippines - Data Privacy Act (DPA) (2012) | 30 → 16 |
| `apac-sgp-cyber-hygiene-practice-2019` | Singapore - Cyber Hygiene Practice (2019) | 21 → 13 |
| `apac-sgp-mas-trm-2021` | Singapore - Monitory Authority of Singapore (MAS) Technology Risk Management (TRM) Guidelines (2021) | 214 → 280 |
| `apac-kor-pipa-2011` | South Korea - Personal Information Protection Act (PIPA) (2011) | 37 → 22 |
| `apac-twn-pdpa-2025` | Taiwan - Personal Data Protection Act (PDPA) (2025) | 23 → 8 |

</details>

### EMEA — 49 frameworks
### EMEA — 47 frameworks

<details><summary>Expand</summary>

Expand All @@ -202,7 +208,6 @@ Or keep using the crosswalk directly:
| `emea-eu-cyber-resilience-act-annexes-2022` | EU Cyber Resilience Act Annexes (CRA Annexes) (2022) | 23 → 117 |
| `emea-eu-eba-ict-srm-2025` | EU EBA Guidelines on ICT and Security Risk Management (2025) | 148 → 150 |
| `emea-eu-nis2-annex-2024` | EU NIS2 Annex (2024) | 223 → 351 |
| `emea-eu-nis2-2022` | EU NIS2 Directive (2022) | 68 → 30 |
| `emea-us-psd2-2015` | EU Second Payment Services Directive (PSD2) (2015) | 30 → 10 |
| `emea-deu-bsrit-2017` | Germany - Banking Supervisory Requirements for IT (2017) | 91 → 93 |
| `emea-deu-c5-2020` | Germany - Cloud Computing Compliance Controls Catalogue (C5) (2020) | 239 → 121 |
Expand Down Expand Up @@ -232,7 +237,6 @@ Or keep using the crosswalk directly:
| `emea-esp-ccn-stic-825-2023` | Spain - ICT Security Guide CCN-STIC 825 (2023) | 99 → 75 |
| `emea-esp-decree-1720-2007` | Spain - Royal Decree 1720/2007 | 17 → 16 |
| `emea-esp-decree-311-2022` | Spain - Royal Decree 311/2022 | 73 → 128 |
| `emea-che-fadp-2025` | Switzerland - FADP | 16 → 9 |
| `emea-tur-lppd-2016` | Turkey - Law on the Protection of Personal Data (LPPD) (2016) | 17 → 10 |
| `emea-uae-niaf-2023` | UAE - National Information Assurance Framework (NIAF) (2023) | 20 → 15 |
| `emea-gbr-caf-4-0` | UK - Cyber Assessment Framework (CAF) (v4.0) | 66 → 66 |
Expand All @@ -247,15 +251,14 @@ Or keep using the crosswalk directly:

</details>

### Global — 86 frameworks
### Global — 84 frameworks

<details><summary>Expand</summary>

| SCF framework ID | Display name | SCF controls → framework controls |
|---|---|---|
| `general-aicpa-pmf-2020` | AICPA Privacy Management Framework (PMF) (2020) | 109 → 123 |
| `general-apec-privacy-framework-2015` | APEC Privacy Framework (2015) | 14 → 25 |
| `amaericas-can-osfi-self-assessment` | Canada - OSFI Cyber Security Self-Assessment Guidance | 141 → 88 |
| `general-coso-2013` | Committee of Sponsoring Organizations (COSO) (2013) | 104 → 17 |
| `general-mpa-csbp-5-3-1` | Content Security Best Practices Common Guidelines (v5.3.1) | 232 → 81 |
| `general-cobit-2019` | Control Objectives for Information and Related Technologies (COBIT) (2019) | 190 → 230 |
Expand Down Expand Up @@ -291,7 +294,6 @@ Or keep using the crosswalk directly:
| `general-mitre-att&ck-16-1` | MITRE ATT&CK (v16.1) | 108 → 511 |
| `general-nist-100-1-ai-rmf` | NIST AI 100-1 (AI RMF 1.0) | 158 → 91 |
| `general-nist-600-1-gen-ai-profile` | NIST AI 600-1 | 139 → 250 |
| `general-nist-csf-2-0` | NIST Cybersecurity Framework (v2.0) | 250 → 134 |
| `general-nist-privacy-framework-1-0` | NIST Privacy Framework (v1.0) | 152 → 122 |
| `general-nist-800-160-vol-2-r1` | NIST SP 800-160 (Vol 2, Rev 1) | 204 → 196 |
| `general-nist-800-161-r1` | NIST SP 800-161 R1 UDP1 | 341 → 308 |
Expand Down