Changelog
Entries are never silently edited — corrections and additions append here, so anything cited from this register can be audited later.
2026-08-11 — v1.25.0: deepened CMMC and UAE PDPL from primary sources. CMMC 1->4: the three-level structure (L1 FCI/17 practices self-assessed; L2 CUI/110 NIST SP 800-171 R2 controls C3PAO-assessed; L3 highest CUI/NIST SP 800-172 subset DIBCAC-assessed), the 32 CFR Part 170 final rule (effective 16 Dec 2024), the phased DFARS rollout (Phase 1 from 10 Nov 2025, Level 2 certification in contracts from 10 Nov 2026), and applicability across the Defense Industrial Base - current-verified given the shifting timeline. UAE PDPL 2->4: lawful processing and consent (Articles 4-6) and the enforcement structure (complaints Art 24, penalties Art 26, and the Executive Regulation provision Art 28), read from the official legislation portal; the Art 28 fact records that the law provides for Executive Regulations without asserting the contested issuance date.
2026-08-11 — v1.24.0: deepened the thin frameworks a coverage audit flagged, from primary sources. NCA ECC (Saudi) 2->5 facts read from the official ECC-2:2024 PDF: the full 4-domain/28-subdomain breakdown, the independent-cybersecurity-department and all-Saudi-staffing governance controls (1-2 per High Order 37140), and the four-part control coding scheme. GDPR 3->6 with Records of Processing (Art 30), DPIA (Art 35-36) and DPO (Art 37-39), cited to the consolidated EUR-Lex text. OWASP ASVS gains the v5.0 17-chapter structure (V1-V17) read from the ASVS 5.0 repository, noting the substantial restructure from v4.0.x.
2026-08-11 — v1.23.0: GCC expansion for the India-to-global programme, from documents read today. UAE PDPL upgraded from official summaries to the issuing legislation portal (uaelegislation.gov.ae) with gazette metadata (issued 20 Sep 2021, Gazette No. 712 supplement, effective 2 Jan 2022, listed Active) plus a new article-map entry covering DPO, breach reporting, data-subject rights, DPIA and cross-border transfer. NCA ECC gains a compliance-mechanism entry (Article 10(3) continuous compliance; self-assessment, compliance-tool reports and field audits; cloud Subdomain 4-2 binding), read from the official ECC-2:2024 PDF, whose structure figures were independently re-confirmed. SAMA deliberately untouched: the framework PDF endpoint returns an error page even in a real browser today, so the rulebook-sourced entry stands unimproved rather than being filled from secondaries.
2026-08-11 — v1.22.1: weekly health remediation. All 14 flagged sources opened in a real browser: 13 confirmed present and re-verified (including the UIDAI AUA/KUA PDF, which the automated check had reported dead - the WAF serves bots HTML but browsers get the PDF). One source genuinely dead: NPCI removed the OC 97 direct PDF; that entry now cites the official UPI circulars listing with the withdrawal noted, matching the sibling entry's treatment. Also fixed: the public GitHub dataset mirror had drifted nine versions behind the site (1.13.0 vs 1.22.0) - synced, and the website deploy now pushes the mirror automatically on version change.
2026-08-08 — v1.22.0: recorded ISO/IEC 27001:2022 bibliographic identity (third edition, October 2022). Content deliberately NOT recorded: the copy available was watermarked as licensed to another organisation and the standard forbids reproduction without permission, so Annex A control counts, clause structure and requirement text are excluded until a copy licensed to CyberSigma is available. The cluster stays thin rather than being filled from material we are not licensed to use.
2026-08-08 — v1.21.0: SOC 2 completed from TSP Section 100 itself. Confirms the TSP Section 100 numbering and ASEC as the issuing committee, both previously omitted. Records the common criteria structure (33 criteria, CC1-CC9) and CORRECTS a near-universal secondary claim: the criteria say the security category is addressed in MOST engagements and expressly contemplate examinations where it is not, rather than making it mandatory.
2026-08-08 — v1.20.0: IRDAI 2026 entries upgraded from corroborated to read-from-the-document (VER 2.0, April 2026, 175 pages). CORRECTED the applicability entry: it had listed brokers, corporate agents, web aggregators, TPAs, ISNPs and IIB from secondary summaries, but the guidelines say Insurers including FRBs and Insurance Intermediaries, and expressly EXCLUDE agents, micro-insurance agents, PoSPs and individual surveyors. Added auditor eligibility (Annexure IV — CERT-In empanelled with CISA/DISA is an accepted route), the 90-day/30-day submission deadline, and the bar on management-representation reliance.
2026-08-08 — v1.19.0: opened the SOC 2 cluster - the largest revenue line with no registry coverage. Only two entries, both sourced from aicpa-cima.com. The detail clients ask about (which category is mandatory, Type 1 versus Type 2, the SSAE 18 / AT-C 205 basis) is not on AICPA's public pages and sits in its paid guide, so it is left OUT rather than written from secondary summaries. SOC 2 turns out to carry the same paywall constraint as ISO.
2026-08-08 — v1.18.0: added the DPDP Consent Manager framework - Rule 4 in force 13 November 2026, First Schedule Part A eligibility and Part B obligations. MeitY blocks automated retrieval (403), so these are corroborated rather than primary-read and each entry says so. The February 2026 amendment rules are NOT recorded as affecting Rule 4: sources disagree on whether that instrument touches DPDP at all.
2026-08-07 — v1.17.0: recorded Regulation (EU) 2026/1744 (Digital Omnibus on AI, in force 27 July 2026), which postpones Annex III high-risk obligations from 2 August 2026 to 2 December 2027 and Annex I embedded-product obligations to 2 August 2028, and adds Article 5 prohibitions on non-consensual intimate imagery. The Article 111 and 113 entries are retained as the enacted text and now cross-reference the amendment. Found because the freshness monitor flagged the page at 86 days against a 30-day SLA.
2026-08-07 — v1.16.0: swept the unguarded single-entry clusters after the IRDAI supersession was missed. Added ISO 22301:2019/Amd 1:2024 and NPCI's TPAP volume-cap deadline of 31 December 2026 plus the OC 215 UPI API guidelines; named the governing Aadhaar regulations and flagged the unread 2025 amendment; recorded the UAE PDPL executive-regulations question as open rather than asserting a contested date.
2026-08-07 — v1.15.0: IRDAI Information and Cyber Security Guidelines, 2023 were superseded on 6 April 2026 by the Information and Cybersecurity Guidelines, 2026 (Version 2.0) - added the current entry and restated the 2023 one as superseded history. Replaced the ISNP entry's homepage citation with an actual IRDAI circular evidencing the governing e-commerce guidelines, and added the CERT-In empanelled expert audit option the previous text omitted.
2026-08-07 — v1.14.0: consolidated the IRDAI cluster — three framework labels (IRDAI, IRDAI (ISNP), IRDAI (India insurance)) merged to one, and removed a duplicate of the Information and Cyber Security Guidelines, 2023 that cited the same instrument, date and source URL as the fuller entry. IRDAI facts now render on /irdai-cybersecurity-audit/, where previously none did.
2026-08-07 — v1.13.0: CKYC (CERSAI) added — 5 entries read from the RBI Master Direction on KYC, 2016 (updated 14 August 2025). Covers CERSAI’s designation as the Central KYC Records Registry by Gazette Notification S.O. 3183(E) of 26 November 2015, the Rule 9(1A) ten-day upload obligation, the phased applicability from the 15 July 2016 live run through to Legal Entity accounts opened on or after 1 April 2021, the Individuals and Legal Entities templates CERSAI revises, and the KYC Identifier download-with-consent mechanism. Added because clients are asking for the service, not because search demand was measurable — with no prior CKYC content the site could not appear for those queries at all.
2026-08-05 — v1.12.0: SWIFT CSP 1 entry -> 7, read from the Customer Security Controls Framework v2026 Detailed Description (1 July 2025). Added the 32-control structure (26 mandatory, 6 advisory, verified both from the stated figure and by counting control identifiers); the KYC-SA attestation window of July to December 2026 against v2026; the five reference architecture types; and the two structural v2026 changes — control 2.4 Back Office Data Flow Security becoming mandatory under the Appendix H phased approach with legacy flows advisory until a tentative 2028, and customer client connectors becoming mandatory in scope for fourteen controls, which moves some users from architecture type B to A4.
2026-08-04 — v1.11.0: PCI DSS 12 entries -> 20. SAQ eligibility criteria added for all nine merchant SAQs plus SAQ D for Service Providers, read from the SAQ Instructions and Guidelines v4.0.1 r1 (April 2025) and the individual v4.0.1 SAQs. Notably, revision r1 of April 2025 ADDED two e-commerce eligibility criteria to SAQ A — payment-page elements must originate only and directly from a compliant third party, and the merchant must confirm its site is not susceptible to script-based attacks — so a merchant that qualified for SAQ A before April 2025 may no longer qualify. Also recorded: SAQs are assessed per payment channel; only SAQ A and A-EP cover e-commerce; and every SAQ except SAQ D for Service Providers excludes service providers.
2026-08-04 — v1.10.0: the five ungated frameworks deepened from 1 entry each to 5, 4, 3, 4 and 3. NIST CSF: six Functions, Core size of 22 Categories and 106 Subcategories counted from the identifiers in NIST CSWP 29, the four Tiers quoted verbatim, and the outcomes-not-controls point that explains why the CSF is not certifiable. EU AI Act: the Article 113 staggered application dates (general application began 2 August 2026), the three Article 99 penalty tiers, and the Article 111 transitional deadlines running to 31 December 2030. GDPR: the Article 33 72-hour breach notification and both Article 83 fine tiers. HIPAA: the 60-calendar-day individual notice, the 500-individual threshold for reporting to the Secretary, and the three classes of Security Rule safeguard, all from the eCFR text current as of 31 July 2026. OWASP ASVS: 345 requirements across 17 chapters and the L1/L2/L3 split, computed from the 5.0.0 requirement set.
2026-08-04 — v1.9.0: PCI DSS 4 entries -> 12, from four PCI SSC documents read in full: the v4.x ROC Template FAQs (rev 1, Dec 2022), the v4.0 DESV Supplemental ROC Template (rev 1, Dec 2022), the v4.x Targeted Risk Analysis Guidance (Nov 2023) and Best Practices for Maintaining PCI DSS Compliance v2.0 (Jan 2019). Added the two assessment approaches and the compensating-control boundary; the four per-requirement findings; the three overall results plus full/partial scope; ROC Template mandatory use and personalisation limits; both kinds of targeted risk analysis; PCI SSC’s suggested TRA frequencies for nine requirements; DESV applicability and cadences; and the three-year evidence-retention recommendation. Three of the four documents sit behind PCI SSC’s licence gate, so they are cited by exact title, revision and date against the document library.
2026-08-04 — v1.8.1: PCI DSS 2 entries -> 4. Added the ten published SAQs (A, A-EP, B, B-IP, C, C-VT, D Merchant, D Service Provider, P2PE, SPoC) and the existence of Integrating Artificial Intelligence in PCI Assessments Guidelines v1.0, both taken from PCI SSC’s own document library and API. The standards themselves sit behind a licence-acceptance gate that blocks automated retrieval, so SAQ eligibility criteria, RoC thresholds and control detail are deliberately NOT recorded — they cannot yet be read from the primary documents.
2026-08-04 — v1.8.0: SEBI CSCRF deepened from 1 entry to 8, every fact read directly from the SEBI circular PDFs. sebi-cscrf-issued is upgraded from FAQ-plus-analyses to the operative extension circular 2025/96 itself. Added: the five RE categories; the requirement that all audits be conducted by a CERT-In empanelled IS auditing organization; VAPT periodicity by NCIIPC designation; VAPT report, closure and revalidation deadlines; the SOC mandate and Market SOC route; Cyber Capability Index applicability; and the 28 August 2025 technical clarifications.
2026-08-04 — v1.7.3: nca-ecc now cites the ECC – 2 : 2024 control document itself rather than the implementation guide. The 108 main controls figure removed in v1.7.2 is restored, having been verified verbatim in the source, and 92 subcontrols added — a figure the entry never carried. Scope wording aligned to the document's own Scope of Work section.
2026-08-04 — v1.7.2: sama-csf and nca-ecc re-sourced to live primary documents. SAMA withdrew its framework PDF; the entry now cites the SAMA Rulebook page carrying the framework text, and the applicability statement is corrected to include credit bureaus and the Financial Market Infrastructure. nca-ecc previously cited the NCA homepage rather than a document; it now cites NCA's published ECC implementation guide, and the unsourced '108 main controls' figure is removed because that guide does not state a control count.
2026-08-04 — v1.7.1: aua-kua-audit re-sourced. UIDAI withdrew the AUA/KUA Agreement v4.0 PDF (now 404), so the fact was pointed at UIDAI's current compliance checklist for controls an AUA/KUA must have in place, which states the annual IS audit obligation directly. The stated fact is unchanged; only its citation moved.
2026-08-02 — v1.7.0: added IRDAI Information and Cyber Security Guidelines 2023 (primary: irdai.gov.in) and NPCI UPI TPAP audit obligations (OC 97; NPCI portal blocks automated retrieval - verified via the official circular listing and corroborating analyses).
2026-08-01 — v1.6.0: added DPDP notice contents (s.5(1), verified from the Gazette), HIPAA Security Rule compliance date, and ISO 22301:2019 publication.
2026-08-01 — v1.5.0: added DPDP Rules breach-notification timeline (Rule 7: without delay + 72-hour detailed report), RBI Cyber Security Framework for Banks (2 June 2016; 2-6 hour incident reporting), and GDPR application date (25 May 2018).
2026-08-01 — v1.4.0: added SWIFT CSP (launched 2016; independent assessment mandatory from 2021), Qatar NIA Policy v2.1 (May 2023), and RBI Digital Payment Security Controls Master Direction (Feb 2021).
2026-08-01 — v1.3.0: added SAMA Cyber Security Framework (May 2017), Saudi NCA ECC-1:2018 / ECC-2:2024, US CMMC programme and acquisition rule dates, and UAE PDPL (Federal Decree-Law 45/2021).
2026-08-01 — v1.2.0: added RBI IT Governance Master Direction (Nov 2023), RBI IT Outsourcing Master Direction (Apr 2023), IRDAI Information & Cyber Security Guidelines 2023, ISO/IEC 42001:2023 publication, EU AI Act commencement and GPAI dates.
2026-08-01 — v1.1.0: added DPDP penalty schedule (verified from the Gazette), SEBI CSCRF issuance and timelines, RBI payment-data localisation, PCI DSS v4.x lifecycle dates, ISO/IEC 27001:2022 transition end, NIST CSF 2.0 release.
2026-08-01 — Initial public release: DPDP Act & Rules phasing, CERT-In Directions obligations, Aadhaar AUA/KUA and IRDAI ISNP audit duties, PCI DSS and OWASP ASVS current versions.