Skip to main content
Framework library

One control graph. Tracked authorities. Explicit standing.

ControlFrame tracks each framework by issuing authority, version, source provenance, catalog availability, and product standing. Where catalog text is licensed or public, candidate mappings are validated by a named reviewer and released only after the framework module’s required activation evidence is approved.

Tracked regimes
84
Parsed catalogs
6
Openable today
6
Evidence spine
1

A source-backed learning instrument

See exactly where authority ends and judgment begins.

Explore one real release from issuing source to normalized catalog, retained assessment context, and named human acceptance. Every station carries its own status; the path never fills a missing fact with a claim.

Open the Catalog Observatory
NIST SP 800-53Rev. 5

Release 5.2.0

AuthorityNIST · Release 5.2.0
Source01f37cf90ea9…6e9bc062
Catalog1,196 catalog units
MethodRetained · inactive
DecisionHuman required
Catalog units
1,196
Active
1,014
Withdrawn
182
Objective nodes
3,715
Source-bound releaseAssessment context retained · inactive

Showing 84 of 84 frameworks

Are we missing a framework?

A missing framework enters governed intake: confirm the authority and catalog licensing, validate parsed controls and candidate mappings, then release the module only after its product standing and activation evidence are approved.

Request a framework review
Modules · standing today
10 modules
ModuleStandingRegistry statusControl unitsOpen
CMS Enhanced Direct Enrollmentrepository-verified reference
Year 9 (PY 2026–PY 2027) · CMS — Direct Enrollment Partners
Implemented
9 evidence lanes
Beta · catalog on disk1,155ingestedOpen module
ARC-AMPE
v1.02 · CMS — Direct Enrollment Entity Resources
Onboardable
10 evidence lanes
Beta · catalog on disk308ingestedOpen module
HITRUST CSF
v11.8.0 · HITRUST Alliance
Acquisition requiredRoadmap · modelledControl count not on recordOpen module
SOC 2
2017 TSC (revised points of focus, 2022) · AICPA — Trust Services Criteria (TSP section 100)
Implemented
9 evidence lanes
Beta · catalog on disk33ingestedOpen module
HIPAA Security Rule
45 CFR Part 164 Subparts A and C · HHS Office for Civil Rights
Onboardable
5 evidence lanes
Beta · catalog on disk65ingestedOpen module
NIST Cybersecurity Framework
2.0 · NIST Cybersecurity Framework
Acquisition requiredRoadmap · modelledControl count not on recordOpen module
ISO/IEC 27001
2022 (Amd 1:2024) · ISO/IEC 27001:2022
Onboardable
5 evidence lanes
Roadmap · modelledControl count not on recordOpen module
ISO/IEC 42001
2023 · ISO/IEC 42001:2023
Acquisition requiredRoadmap · modelledControl count not on recordOpen module
PCI DSS
v4.0.1 · PCI Security Standards Council
Onboardable
12 evidence lanes
Beta · catalog on disk250ingestedOpen module
FedRAMP (Rev. 5 baselines)
Rev. 5 · FedRAMP
Acquisition requiredRoadmap · modelledControl count not on recordOpen module
Implemented
A project opens into working evidence lanes, and collection runs against a real target — a registered test plan or a production release path.
Onboardable
A project opens into evidence lanes with a real control set behind them; collection is demonstrative until a test plan runs against a real target.
Acquisition required
Named, with the authority's acquisition path recorded; onboarding is refused until a control set is registered.
Directory entry
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

Control units are the regime’s native units and carry their basis on hover — ingested means a control set is on disk or in a blueprint; published means the authority states the figure and we have not ingested the text. Evidence state is a tenant fact: it is shown inside the workspace against the tenant’s own catalog, never on this public page. Registry status follows the registry’s own contract: Beta Parsed catalog: a source-pinned control or requirement catalog for this regime exists in the repo. `catalogPath` is non-null and `controlCount` is real. This does not mean tenant workflows are activated or that an assurance outcome has been earned. Roadmap Modeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested. Planned Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.

Tenant-authored frameworks

No tenant-authored frameworks in this session. Bring a control catalog — a CSV export or an OSCAL JSON file — and it joins the library above without a release. A PCI DSS v4.0.1 excerpt and an explicitly archived NIST SP 800-53 Rev. 5 Release 5.1.1 parser fixture are loadable from the import desk; the source-pinned Release 5.2.0 catalog is available in the public Observatory, not as a tenant onboarding template.

Evidence reuse · one artifact, native and candidate
EV-2048consent-confirmation-event.jsonsha256:8df1…a43c · REV-218 · Reviewer 01 · accepted
Evidence mappings for the reference artifact
FrameworkControl referenceControl titleReview standing
CMS EDEY9 · UI-3.2Consumer consent flow and retained confirmationNative · accepted
CMS EDEY5 · AUD-1.1Enrollment transaction audit recordNative · accepted
NIST CSF 2.0DE.CM-09Computing activity and technology usage monitoringCandidate · reviewer confirmation pending
NIST CSF 2.0PR.DS-01Confidentiality, integrity, and availability of data at restCandidate · reviewer confirmation pending
HIPAA164.312(b)Audit controlsCandidate · reviewer confirmation pending
HIPAA164.312(c)(1)IntegrityCandidate · reviewer confirmation pending

Accepted once under the native regime; proposed, not presumed, under the next one. A named reviewer accepts or rejects every candidate mapping before it counts. Inspect the control crosswalk

Change record · when the regulator moves
MARS-E 2.2ARC-AMPE v1.02NIST SP 800-53 Rev 4 tailoringNIST SP 800-53 Rev 5 tailoringOpen the diff
41
added
26
removed
76
renumbered or retitled
2
families with no Rev 4 ancestor

CMS retired MARS-E 2.2 and replaced it with ARC-AMPE — a different NIST catalog under the same program name. Two control families in the new baseline have no Rev 4 ancestor at all, so no legacy artifact can answer them. The diff is derived from the two catalogs rather than announced; what it costs an evidence program is projected on the change page, in a labeled synthetic-reference mode or against a tenant’s own catalogs.

Frameworks | ControlFrame