top of page

MAIS CONFORMANCE LEVELS

v0.1 — Draft for public comment

 

A standard that no one can claim alignment with generates no shared benefit. MAIS therefore defines three levels at which an organisation, consultancy or vendor may describe its relationship to the standard.

 

These are self-declared statements of practice. PRAECEPTA does not assess, approve, certify or accredit conformance, and does not maintain a register of conformant parties. No fee is payable and no permission is required.

Level 1 — MAIS-Referenced

 

You may state that your work is MAIS-Referenced if you:

  1. Cite the MEA Assurance Interoperability Standard in the work; and

  2. Attribute PRAECEPTA Cybersecurity LLC in accordance with the CC BY 4.0 licence; and

  3. State the MAIS version referenced.

 

Typical adopters: analysts, academics, consultancies, and authors of comparative framework material.

Level 2 — MAIS-Aligned

 

You may state that your organisation is MAIS-Aligned if you:

  1. Meet all Level 1 requirements; and

  2. Use MAIS Evidence Primitive identifiers as the organising unit of your own evidence register; and

  3. Record, for each primitive, a named accountable owner and a refresh cadence; and

  4. Maintain the mapping from each primitive to the framework units it contributes to.

 

What this means in practice: your evidence base is structured around what you must prove, not around any single framework's chapter order. A framework revision therefore changes your mapping, not your evidence collection.

 

Typical adopters: regulated organisations operating under three or more frameworks.

Level 3 — MAIS-Conformant

 

You may state that your product or service is MAIS-Conformant if you:

  1. Meet all Level 2 requirements; and

  2. Implement an assessment grammar that derives each framework's native verdict from primitive response states, rather than presenting a single merged or averaged score; and

  3. Publish, or make available to your users, a Delta Register identifying where convergence between the frameworks you support is not achievable, and why; and

  4. Publish the version of each framework you model, and the basis on which that version was verified; and

  5. Where you publish a convergence figure, publish the denominator and the basis of calculation with it.

 

What this means in practice: you do not present a merged score, you do not claim complete convergence, and you tell your users which framework version you model and how you know.

 

Typical adopters: GRC platform vendors, assurance consultancies, and internal assurance functions building their own tooling.

What conformance is not

  • It is not a certification, accreditation, or assurance opinion.

  • It is not assessed, approved or verified by PRAECEPTA.

  • It does not indicate compliance with any law, regulation or framework.

  • It does not imply endorsement by PRAECEPTA of any product, service or organisation.

 

Determinations of regulatory compliance and certification rest solely with the relevant regulatory authority, accredited certification body, or appointed auditor.

Why we define these levels

 

Because the alternative is worse. Without defined levels, every adopter invents their own claim, and "MAIS-based" comes to mean nothing. With them, a reader can tell the difference between a consultancy that cited the taxonomy and a platform that implemented the grammar.

 

Level 3 is deliberately demanding. It requires a vendor to publish its gaps and its framework versions — the two things this market is least willing to disclose. That is the point.

 

Comments on these levels: 

bottom of page