
FRAMEWORKS & VERSION CONTROL
MAIS references frameworks by control identifier only. We reproduce no framework text. Framework names, identifiers and content remain the property of their respective issuing authorities, and reference does not imply endorsement or affiliation.

Modelled in v0.1
Frameworks modelled in MAIS v0.1
Our version commitment. This register is reviewed monthly and on notification of any revision by an issuing authority. MAIS content changes when a regulator changes a framework — not because our documentation was imprecise.
Why there are no control counts on this page. Control, domain and outcome counts are held in versioned data files and rendered into our deliverables, not written into this website. A framework revision is therefore absorbed by a data change, not a rewrite — and this page cannot silently go stale.
Frameworks are referenced by control identifier only. No framework text is reproduced. Framework names and identifiers remain the property of their respective issuing authorities. Reference does not imply endorsement, affiliation, approval or accreditation by any issuing authority.
OUR VERSION COMMITMENT
This register is reviewed monthly and on notification of any revision by an issuing authority. MAIS content changes when a regulator changes a framework — not because our documentation was imprecise. Framework detail lives in versioned data files, so a revision is absorbed by a data change and a re-generation, not a rewrite.
Where public information about a framework is inconsistent — as is currently the case for one framework in our scope — we record it as pending primary verification and publish no structural detail until we hold the issuing authority's own document. We would rather be incomplete than wrong.
ROADMAP
Candidate frameworks for subsequent releases, sequenced by design-partner demand: CBUAE Cybersecurity Framework · NCA Cloud Cybersecurity Controls and Operational Technology Cybersecurity Controls · Qatar National Information Assurance framework · Central Bank of Bahrain Cybersecurity Framework · IEC 62443 for OT and industrial environments · DORA and NIS2 for European exposure · and privacy instruments including the Saudi PDPL, UAE and free-zone data-protection regimes, Bahrain PDPL, Kenya's Data Protection Act 2019, Nigeria's NDPR and South Africa's POPIA.
Privacy is modelled as a cross-cutting overlay, not as an additional framework — because privacy obligations attach to data-handling evidence that security frameworks already require.
