
MAIS
[ MEA Assurance Interoperability Standard ]
ASK ONCE. BE ASSESSED EVERYWHERE.
PRAECEPTA is building the open standard that lets organisations across the Middle East and Africa satisfy multiple cybersecurity frameworks from a single evidence base — each framework answered in its own language.
[Read the standard →] [Become a design partner →]

Five frameworks. One reality. Five bills.
A regulated organisation in the Gulf may answer simultaneously to Saudi Arabia's Essential Cybersecurity Controls, SAMA's Cyber Security Framework, the UAE Information Assurance Standard, ISO/IEC 27001, and NIST CSF — and, with UK or EU exposure, the NCSC Cyber Assessment Framework.
The frameworks overlap heavily. The assessments do not. So the same evidence is gathered, formatted, reviewed and defended several times over — by the same small team, in the same quarter.
Mapping is solved. Assessment is not.
Good crosswalks exist, some of them free. We use relationship semantics consistent with NIST IR 8477 ourselves. But a crosswalk answers "are these two controls related?" — and organisations do not fail assessments for lack of a mapping table.
The unanswered question is the expensive one: given this evidence, what verdict does each framework return? One framework judges outcomes against indicators of good practice, where a single unmet indicator blocks a positive determination. Another determines control implementation. Another grades maturity across six levels. Another weights applicability by risk tier.
One answer. Five incompatible verdicts. That translation is what MAIS builds.
Evidence Primitives. We decompose assurance into atomic evidentiary conditions rather than controls — because cost is incurred producing evidence, not reading control text. De-duplicating evidence is what reduces effort.
Assessment Grammar Transform. Each framework's native evaluation logic, held as executable rules. This is where a single response becomes six correct, framework-specific verdicts.
Delta Register. The published record of where convergence is not achievable, and why. We compute the residual from our own data and publish it. Anyone claiming complete convergence across these frameworks has not read them closely.
Open standard. Proprietary engine. Tool-agnostic.
The MAIS taxonomy is published under CC BY 4.0 — free to use, adapt and build upon, including commercially. A regional assurance standard should be a shared asset. We would rather author it than rent it.
MAIS sits beneath your GRC platform, not in place of it. If you have already invested in compliance tooling, keep it. Our output is a governed workbook, diagram-as-code architecture, board reporting, and machine-readable OSCAL your existing toolchain can consume.
We publish our version discipline
Every framework we model is recorded with its exact version, issuer and verification status. We reference frameworks by control identifier only and reproduce no framework text. Where we cannot verify a framework's structure against the issuing authority's own document, we publish nothing and say so.
Five design partners. Then v1.0.
We are recruiting five regulated, multi-framework organisations across Saudi Arabia, the UAE and the wider region to test MAIS against real assessment cycles.
[ Conformance Levels → ] [ Versioning → ]
