Problem
An auditor or a CISO who imports NIST 800-53 into OpenRisk gets 20 rows, not the roughly 1,000 controls the standard defines. They cannot run an assessment on that, and it is the first thing a buyer checks against Vanta, Drata or ServiceNow.
Rows per catalogue in backend/pkg/compliance/catalog_*.go on 2026-09-25:
| Catalogue |
Rows |
What the rows are |
Real granularity |
iso27001-2022 |
93 |
Annex A controls |
93 ✅ |
nist-800-53-r5 |
20 |
control families (AC, AU, …) |
about 1,000 controls and enhancements |
cis-v8 |
18 |
top-level controls |
153 safeguards |
pci-dss-4.0 |
12 |
principal requirements |
about 250 sub-requirements |
nis2-2022-2555 |
12 |
Art. 21(2) measures |
Art. 21(2) plus Implementing Reg. (EU) 2024/2690 annex |
dora-2022-2554 |
19 |
articles |
articles plus RTS on ICT risk management |
sox-2002 |
10 |
sections |
— |
TestExpectedControlCounts does not cover the three African catalogues either (see claim C-005), so none of these counts is locked.
Licensing — checked before any content is written
Depth is not only a matter of effort:
- NIST SP 800-53 r5 is a US Government work, and NIST publishes an official OSCAL catalogue. It can be imported, not transcribed.
- NIS2 and DORA are EU law; the official text in EUR-Lex can be cited.
- CIS Controls v8 is licensed CC BY-NC-ND 4.0. Shipping safeguard text in a product sold under
LICENSE.commercial probably needs CIS permission.
- PCI DSS text is copyrighted by PCI SSC.
So CIS and PCI are not in this issue's scope. Whether to ship reference-only rows (identifier plus our own wording) or to seek permission goes to the owner as D-057 in docs/DECISIONS.md (licensing).
Acceptance criteria
nist-800-53-r5 is generated from NIST's official OSCAL JSON (moderate baseline at minimum; the PR records which baseline). A script under backend/cmd/ or scripts/ regenerates it, and each row keeps its control id (AC-2, AC-2(1), …) plus the source URL.
nis2-2022-2555 covers every item of Art. 21(2)(a)-(j), Art. 23 (reporting) and the technical requirements of the annex to Implementing Regulation (EU) 2024/2690. Each row cites its article or paragraph.
dora-2022-2554 covers the ICT risk-management framework articles (Art. 5-16), incident reporting (Art. 17-23), resilience testing (Art. 24-27) and third-party risk (Art. 28-30). Each row cites its article.
TestExpectedControlCounts locks the count of every catalogue, the three African ones included (closes the first gap noted on C-005).
- The existing crosswalks (
internal/domain/control_crosswalk.go) still resolve after the import. Tenants who already imported the old 20-row NIST catalogue keep their data, and the upgrade path (additive import, no deletion) is tested.
- No row is written from memory: each one points to the official source text (the D-002 rule).
Definition of Done
A user can import NIST 800-53 (moderate), NIS2 or DORA and assess at control level. The counts are locked by a green test, and the command and its output are pasted on this issue.
Problem
An auditor or a CISO who imports NIST 800-53 into OpenRisk gets 20 rows, not the roughly 1,000 controls the standard defines. They cannot run an assessment on that, and it is the first thing a buyer checks against Vanta, Drata or ServiceNow.
Rows per catalogue in
backend/pkg/compliance/catalog_*.goon 2026-09-25:iso27001-2022nist-800-53-r5cis-v8pci-dss-4.0nis2-2022-2555dora-2022-2554sox-2002TestExpectedControlCountsdoes not cover the three African catalogues either (see claim C-005), so none of these counts is locked.Licensing — checked before any content is written
Depth is not only a matter of effort:
LICENSE.commercialprobably needs CIS permission.So CIS and PCI are not in this issue's scope. Whether to ship reference-only rows (identifier plus our own wording) or to seek permission goes to the owner as D-057 in
docs/DECISIONS.md(licensing).Acceptance criteria
nist-800-53-r5is generated from NIST's official OSCAL JSON (moderate baseline at minimum; the PR records which baseline). A script underbackend/cmd/orscripts/regenerates it, and each row keeps its control id (AC-2,AC-2(1), …) plus the source URL.nis2-2022-2555covers every item of Art. 21(2)(a)-(j), Art. 23 (reporting) and the technical requirements of the annex to Implementing Regulation (EU) 2024/2690. Each row cites its article or paragraph.dora-2022-2554covers the ICT risk-management framework articles (Art. 5-16), incident reporting (Art. 17-23), resilience testing (Art. 24-27) and third-party risk (Art. 28-30). Each row cites its article.TestExpectedControlCountslocks the count of every catalogue, the three African ones included (closes the first gap noted on C-005).internal/domain/control_crosswalk.go) still resolve after the import. Tenants who already imported the old 20-row NIST catalogue keep their data, and the upgrade path (additive import, no deletion) is tested.Definition of Done
A user can import NIST 800-53 (moderate), NIS2 or DORA and assess at control level. The counts are locked by a green test, and the command and its output are pasted on this issue.