
THE DELTA REGISTER
Where frameworks cannot be reconciled — and why
Every vendor in this market claims coverage. Almost none publishes the gaps. We think that is the wrong way round.
Convergence across the frameworks MAIS models is substantial and it is measurable. We compute it from our own primitive and mapping data rather than asserting a number, and it is shown below alongside the version of the data that produced it. What matters more is the residual — the requirements that genuinely cannot be satisfied from a shared evidence base. Knowing exactly what those are, and why, is worth more than being told they do not exist.
Convergence — not yet published
MAIS v0.1 models two evidence domains across six frameworks. The convergence figure is computed from primitive-to-framework bindings, not asserted.
Those bindings are being finalised against primary source documents. We do not publish a computed figure until its inputs are verified.
When we publish the figure, we will publish the denominator and the basis of calculation with it, or not at all. A convergence percentage without a stated denominator is not a measurement.

Categories of irreducible divergence
1. Sovereign and national obligations. Requirements arising from national data-residency, localisation, and reporting obligations in Saudi Arabia and the UAE have no counterpart in ISO/IEC 27001:2022, NIST CSF 2.0 or NCSC CAF v4.0. These are not gaps in the international frameworks — they are gaps by design. They must be evidenced natively and cannot be inherited from an international certification. This is the single most common and most costly misconception we encounter in the region.
2. Paradigm mismatch. Maturity-graded frameworks require evidence of measurement, metrics and demonstrable continuous improvement in order to reach their upper grades. Compliance-based frameworks require no such evidence. An organisation can be fully implemented against a compliance framework and still sit at a low maturity grade — legitimately, and with no error on either side. Reconciling these is not a mapping exercise. It is a transformation, and it needs additional evidence that only the maturity framework demands.
3. Newer outcome expectations. NCSC CAF v4.0 raised expectations on understanding adversary methods and motivations, secure software development and support, behavioural and threat-intelligence-informed monitoring, and structured threat hunting. In our mapping work we did not identify equivalent-granularity requirements for several of these in the regional frameworks in scope. Organisations pursuing both must produce evidence that only one framework asks for.
4. Management-system obligations. Certification against a management-system standard requires documented justification of applicability and evidence of system operation, distinct from technical control implementation. This is a genuinely separate evidence class.
How to read this. "Not identified at comparable granularity" states what our mapping found, not that a framework is deficient. Frameworks differ by design and by mandate. What matters commercially is that these requirements must be resourced separately regardless of what any platform promises about coverage.
Extract from MAIS v0.1. Full register published with the specification.
HOW TO USE THIS PAGE
If you are budgeting a multi-framework assurance programme, the Delta Register tells you which portion of your effort is genuinely shared, and which portion you must resource separately regardless of what any platform promises. That is a planning input, not a marketing claim.
