
DESIGN PARTNER PROGRAMME
Five organisations. One standard. Shaped by the people who have to live with it.
MAIS v0.1 is a draft. Draft standards written without practitioners become shelfware, so we are recruiting five design partners to test MAIS against real assessment cycles before we publish v1.0.

Who we are looking for
-
Regulated organisations in Saudi Arabia, the UAE, or the wider Middle East and Africa
-
Currently answering to three or more cybersecurity frameworks
-
Financial services, energy, government, telecommunications, healthcare or critical national infrastructure
-
A named sponsor at CISO level or above, and a working-level assurance or GRC lead
-
Willing to be credited in the published standard (optional — anonymous participation is available)
What you receive
-
A full unified assessment across your framework portfolio for the domains modelled, delivered as a governed workbook with native verdicts per framework.
-
Your organisation's Delta Register — the specific requirements you must evidence separately, with reasons. A budget input you can take to your board.
-
A perpetual internal-use licence to the Assessment Grammar Transform engine for the frameworks in your scope.
-
Direct authorship influence over v1.0, including framework prioritisation.
-
Machine-readable OSCAL export of your assessment for ingestion into your existing toolchain.
-
Credit in the published standard
What we ask
-
Access to your existing assessment evidence under NDA, for the modelled domains
-
Roughly one working session per fortnight over a ten-week cycle
-
Candid, structured feedback — including where the method does not work
-
Permission to publish anonymised, aggregated convergence findings
What this is not
This is not a free consultancy engagement, and it is not a software pilot with a purchase obligation. It is a research collaboration with defined deliverables and a defined end. There is no obligation to buy anything, ever.
We are open about the exchange: you get an unusually rigorous assessment and a perpetual licence; we get the practitioner input that makes the standard credible.
