
METHODOLOGY
Why we de-duplicate evidence, not controls
The industry de-duplicates controls. That is the wrong unit. No organisation's cost sits in reading control text — it sits in producing, formatting, reviewing and defending evidence, repeatedly, to different assessors, in different formats, on different cycles.
So MAIS models the evidence artefact as the atom. When two frameworks depend on the same underlying fact, the fact is asserted once, the artefact is produced once, and the verdict is derived independently for each framework. That is where effort actually falls away.

Assessment paradigms — the technical crux
Frameworks in scope do not merely differ in content. They differ in kind:
These are not interchangeable, and no mapping table can make them so. A maturity grade cannot be crosswalked to a binary determination; it can only be transformed, and only if you model what evidence each grade demands. This is the case for the Assessment Grammar layer, and it is the reason MAIS exists.
Why we model NCSC CAF v4.0
Three reasons. Many MEA organisations have UK or EU parentage, or supply into those markets. Outcome-based supervision is the direction of travel in critical-infrastructure regulation generally. And CAF v4.0's evaluation logic is the strictest in our scope — which makes it the most demanding test of any interoperability claim. Modelling it forces the method to be honest. CAF v4.0 also sharpened expectations on threat understanding, secure software development, behavioural monitoring and threat hunting, and threaded AI-related risk across the framework rather than isolating it — expectations that expose genuine gaps when set against regional frameworks. Those gaps are in our Delta Register, named.
Provenance
Every mapping in MAIS records the source document title, its version, its publication date, the referenced clause identifier, the retrieval date, the author, and the verification status. Nothing enters MAIS on the authority of a blog post, a vendor summary, or a secondary interpretation. Where the public record is inconsistent, we mark the framework pending primary verification and publish no detail until we have the issuing authority's own document.
This is slower. It is also the difference between a methodology and a marketing artefact.
What MAIS does not do
-
It does not certify, accredit, or determine compliance. Those functions belong to regulators, accredited certification bodies and appointed auditors.
-
It does not eliminate assessment. It removes duplicated evidence effort and makes residual divergence explicit.
-
It does not achieve total convergence. Sovereignty and data-residency obligations have no counterpart in international frameworks, and paradigm differences are irreducible. We publish the residual rather than conceal it.
