Framework registry
Versioned control truth for CTM-first expansion into SOC 2, ISO 27001, and ISO 42001.
Fixture

Evidence graph foundation

Frameworks are now tracked as reproducible versions with requirements, controls, and evidence requirements split into separate objects.

1
1
189
371

CTM 2025 Pillar Coverage

Fixture - 2026-06-06T00:00:00Z
Singapore-first expansion map

CTM evidence is split into classical, cloud, OT, and AI-security obligations before it is reused into SOC 2, ISO 27001, and ISO 42001 expansion work.

189Assessable
37AI controls
11AI risks
2AI reuse paths
ClassicalClassical cybersecurity

Base CTM requirements and evidence that remain reusable across every expansion path.

189 controls371 evidence asks22 domains
advocate: 58performer: 56practitioner: 25promoter: 37supporter: 13
SOC2-TSCISO27001:2022
CloudCloud security

Cloud-specific extension obligations that strengthen ISO 27001 and SOC 2 cloud scope.

49 controls98 evidence asks18 domains
advocate: 11performer: 17practitioner: 5promoter: 14supporter: 2
SOC2-TSCISO27001:2022
OTOT security

Operational-technology obligations for critical infrastructure and cyber-physical estates.

59 controls116 evidence asks21 domains
advocate: 13performer: 21practitioner: 5promoter: 16supporter: 4
ISO27001:2022CTM sector scope
AIAI security

AI-security obligations that form the local evidence bridge into ISO 42001 AIMS work.

37 controls71 evidence asks15 domains
advocate: 10performer: 11promoter: 14supporter: 2
ISO42001:2023NIST AI RMF
B.9 - Data protection and privacy12 assessable controls
Classical 12Cloud 4OT 4AI 4
B.1 - Governance6 assessable controls
Classical 6Cloud 3OT 3AI 5
B.3 - Risk management12 assessable controls
Classical 12Cloud 3OT 4AI 4
B.12 - System security13 assessable controls
Classical 13Cloud 4OT 4AI 2
B.16 - Cyber threat management8 assessable controls
Classical 8Cloud 3OT 5AI 2
B.18 - Vulnerability assessment9 assessable controls
Classical 9Cloud 4OT 4AI 1
B.1.3 - Understanding the importance of cybersecurity

Such practices include establishing mechanisms for: – The organisation to provide necessary security information about its AI systems to users and other relevant stakeholders, e.g., acceptable use policy of the AI systems in the organisation; and – Employees and external parties to report AI security concerns of the AI systems in the organisation.

promotermanual_task2 evidence
B.1.4 - Defining roles and responsibilities

The organisation has defined and allocated roles and responsibilities for AI security due to the multidisciplinary nature of AI, which can cut across various organisational functions, e.g., functions overseeing ethics, legal matters, and risk areas.

performermanual_task2 evidence
B.1.5 - Board and/or senior management involvement

The Board and/or senior management should have sufficient expertise in AI security to make appropriate business decisions that take into consideration the implications associated with the specific risks of AI, e.g., over-reliance on AI.

performermanual_task2 evidence
B.1.6 - Meeting cybersecurity objectives

This includes identifying and documenting the objectives to guide the secure use of AI system(s) and ensuring these system(s) are used according to the intended purposes.

performermanual_task2 evidence
B.1.7 - Forming cybersecurity committee/forum

The cybersecurity committee/forum has implemented measures to stay updated on fast-evolving AI security practices and governance landscapes, e.g., participating in AI special interest groups.

advocatemanual_task2 evidence
B.12.4 - Implementing process for the application of secure configuration

As part of secure configuration, the organisation has considered AI model complexity and the appropriateness of the model for the intended use case, as complex models may involve additional software packages or libraries, which expand the attack surface.

promoterconnector_check2 evidence

Registry

tnt_demo
FrameworkStatusJurisdictionRequirementsControlsEvidenceRetrieved
Cyber Trust mark self-assessment checklist v202504
CSA-CTM-self-assessment-v202504
activeSG1891893712026-06-06 00:00:00Z

Evidence Reuse Graph

ctm-ss712-2025-placeholder.v1
CTM to target frameworks

Tenant evidence is resolved through the authored crosswalk before standalone SOC 2, ISO 27001, or ISO 42001 modules are sold.

11Covered
0Weak
0Stale
0Missing
ISO27001:2022 A.5.1

GOV-1

coveredhigh1 evidence
ISO27001:2022 A.5.24

IR-2

coveredhigh2 evidence
ISO27001:2022 A.5.9

ASM-1

coveredhigh1 evidence
ISO27001:2022 A.8.15

LOG-1

coveredhigh2 evidence
ISO27001:2022 A.8.24

DP-1

coveredhigh2 evidence
ISO27001:2022 A.8.5

AC-1

coveredhigh2 evidence
SOC2-TSC CC1.1

GOV-1

coveredmedium1 evidence
SOC2-TSC CC6.1

AC-1, ASM-1

coveredhigh3 evidence
SOC2-TSC CC6.7

DP-1

coveredmedium2 evidence
SOC2-TSC CC7.2

LOG-1

coveredhigh2 evidence
SOC2-TSC CC7.3

IR-2

coveredhigh2 evidence

Evidence Quality

Fixture - 2026-06-04T00:00:00Z
Average evidence strength
66

Scores combine source method, freshness, result state, human review, parser confidence, integrity, and scope traceability before evidence is reused for SOC 2, ISO 27001, or ISO 42001.

high0
medium8
low2
poor0
GOV-1

tnt_demo/manual/GOV-1/governance-charter-2026.pdf

low45/100
Hash, signature, and storage integrityEvidence has available source or artifact traceability.
DP-1

tnt_demo/manual/DP-1/encryption-and-backup-policy.pdf

low50/100
Hash, signature, and storage integrityEvidence has available source or artifact traceability.
AC-1

okta:access_review

medium69/100
Human review and rejection historyNo human review decision is recorded yet.
AC-1

okta:mfa_privileged

medium69/100
Human review and rejection historyNo human review decision is recorded yet.
ASM-1

aws:asset_inventory

medium69/100
Human review and rejection historyNo human review decision is recorded yet.
DP-1

crowdstrike:device_encryption

medium69/100
Human review and rejection historyNo human review decision is recorded yet.

Evidence Provenance

Fixture - 2026-06-04T00:00:00Z
Assessor-grade traceability

Evidence is tracked by source, freshness, review state, parser confidence, and hash/receipt proof before it is reused in CTM, SOC 2, ISO 27001, or ISO 42001 packs.

0%Ready trace
1Refresh
10Unreviewed
0Receipts
AC-1 - okta:access_review

connector - Expiring in 16d

Review needed
69 score- parser0 artifacts0 receipts
Human reviewno review - no artifact hash
AC-1 - okta:mfa_privileged

connector - Fresh for 85d

Review needed
69 score- parser0 artifacts0 receipts
Human reviewno review - no artifact hash
ASM-1 - aws:asset_inventory

connector - Fresh for 83d

Review needed
69 score- parser0 artifacts0 receipts
Human reviewno review - no artifact hash
DP-1 - crowdstrike:device_encryption

connector - Fresh for 86d

Review needed
69 score- parser0 artifacts0 receipts
Human reviewno review - no artifact hash
DP-1 - tnt_demo/manual/DP-1/encryption-and-backup-policy.pdf

manual - Fresh for 340d

Review needed
50 score- parser0 artifacts0 receipts
Human reviewno review - no artifact hash
GOV-1 - tnt_demo/manual/GOV-1/governance-charter-2026.pdf

manual - Open-ended

Review needed
45 score- parser0 artifacts0 receipts
Human reviewno review - no artifact hash
IR-2 - crowdstrike:edr_coverage

connector - Fresh for 86d

Review needed
69 score- parser0 artifacts0 receipts
Human reviewno review - no artifact hash

Framework Expansion Planner

Fixture - 2026-06-04T00:00:00Z
Buyer-ready expansion view

CTM evidence is translated into an expansion offer: reuse potential, weak or stale proof, reviewer workload, net-new collection, auditor questions, and export readiness.

100%Reusable
0Net new
11Review / weak
11Owner hours
CTM to ISO 27001

ISMS expansion bridge - ISO27001:2022

Medium riskPlan ready

CTM to ISO 27001: 100% of target requirements have CTM evidence reuse potential. 0 are export-ready, 0 need refresh or strengthening, 6 need reviewer sign-off, and 0 are net-new.

100%Reuse
0Weak/stale
0New
6Hours
Service effortOne focused readiness sprint
Export readinessReview queue

Auditor asks

  • Confirm scope, reviewer sign-off, and whether the evidence period matches ISO27001:2022 for A.5.1.
  • Confirm scope, reviewer sign-off, and whether the evidence period matches ISO27001:2022 for A.5.24.
  • Confirm scope, reviewer sign-off, and whether the evidence period matches ISO27001:2022 for A.5.9.

Sprint backlog

  • Run reviewer sign-off for 6 mapped controls.
A.5.1

GOV-1 - Compliance lead

Review45/100
A.5.24

IR-2 - Security operations

Review73/100
A.5.9

ASM-1 - Infrastructure owner

Review69/100
A.8.15

LOG-1 - Infrastructure owner

Review73/100
CTM to SOC 2

Type II readiness bridge - SOC2-TSC

Medium riskPlan ready

CTM to SOC 2: 100% of target requirements have CTM evidence reuse potential. 0 are export-ready, 0 need refresh or strengthening, 5 need reviewer sign-off, and 0 are net-new.

100%Reuse
0Weak/stale
0New
5Hours
Service effortOne focused readiness sprint
Export readinessReview queue

Auditor asks

  • Confirm scope, reviewer sign-off, and whether the evidence period matches SOC2-TSC for CC1.1.
  • Confirm scope, reviewer sign-off, and whether the evidence period matches SOC2-TSC for CC6.1.
  • Confirm scope, reviewer sign-off, and whether the evidence period matches SOC2-TSC for CC6.7.

Sprint backlog

  • Run reviewer sign-off for 5 mapped controls.
CC1.1

GOV-1 - Compliance lead

Review45/100
CC6.1

AC-1, ASM-1 - IT / IAM owner

Review69/100
CC6.7

DP-1 - IT / IAM owner

Review69/100
CC7.2

LOG-1 - Security operations

Review73/100
CTM to ISO 42001

AI Governance Add-on - ISO42001:2023

Model requiredModel required

CTM to ISO 42001 / AI Governance Add-on is visible as a roadmap offer, but ISO42001:2023 needs authored requirements and reviewed CTM mappings before CyberG7 should quote a readiness plan.

0%Reuse
0Weak/stale
0New
0Hours
Service effortFramework modeling sprint before customer estimate
Export readinessModel first

Auditor asks

  • Which target requirements and mappings are in scope for this offer?
  • Which CTM controls can be reused once the model is authored?
  • What evidence types will the assessor accept for this framework?

Sprint backlog

  • Author the target-framework object model and requirement mappings.
  • Review CTM-to-target evidence reuse assumptions before quoting effort.
  • Define auditor evidence expectations before customer delivery starts.

No authored crosswalk rows are loaded for this target framework yet; build the framework object model and reviewed mappings before estimating net-new evidence.

SOC 2 Observation Ledger

Fixture - 2026-01-01T00:00:00Z to 2026-06-30T00:00:00Z
Type II operating-period proof

The ledger separates point-in-time readiness from observation-window evidence: recurring checks, missed checks, sample populations, selected samples, exceptions, and management responses.

0Operating
0Exceptions
10Samples
180Days
SOC2-TSC CC6.1

AC-1, ASM-1

Insufficient
3/6 checks3 samples4 exceptions
response requiredcontrol owner TBD
SOC2-TSC CC6.7

DP-1

Insufficient
2/6 checks2 samples3 exceptions
response requiredcontrol owner TBD
SOC2-TSC CC7.2

LOG-1

Insufficient
2/6 checks2 samples3 exceptions
response requiredcontrol owner TBD
SOC2-TSC CC7.3

IR-2

Insufficient
2/6 checks2 samples3 exceptions
response requiredcontrol owner TBD
SOC2-TSC CC1.1

GOV-1

Insufficient
1/2 checks1 samples2 exceptions
response requiredcontrol owner TBD

SOC 2 Workflow Evidence

Fixture - 2026-01-01T00:00:00Z to 2026-06-30T00:00:00Z
Audit workflow proof

Workflow families connect operating-period evidence to the records auditors usually sample: access reviews, terminations, incidents, vulnerability remediation, change management, vendor risk, and security awareness.

0Ready
5Review
2Missing
12Samples
4Missed
0Exceptions
Vulnerability Remediation

CC7.1, CC7.2 · ASM-1, LOG-1

Review
monthly3/6 periods3 missed0 exceptions3 evidence3 samples6 gaps
Strengthen tracenot required
Vendor Risk Review

CC9.2 · mapping required

Missing
annual0/1 periods1 missed0 exceptions0 evidence0 samples1 gaps
Collect evidencenot required
Access Review

CC6.1 · AC-1, ASM-1

Review
quarterly3/2 periods0 missed0 exceptions3 evidence3 samples6 gaps
Strengthen tracenot required
Access Termination

CC6.1 · AC-1, ASM-1

Review
event driven3/3 periods0 missed0 exceptions3 evidence3 samples6 gaps
Strengthen tracenot required
Incident Response

CC7.3 · IR-2

Review
event driven2/2 periods0 missed0 exceptions2 evidence2 samples4 gaps
Strengthen tracenot required
Security Awareness

CC2.2 · GOV-1

Review
annual1/1 periods0 missed0 exceptions1 evidence1 samples2 gaps
Strengthen tracenot required

ISO 27001 ISMS Readiness

Fixture - 2026-01-01T00:00:00Z to 2026-06-30T00:00:00Z
Management-system records

ISO 27001 readiness needs more than Annex A evidence. This view tracks scope, risk, treatment, SoA, policy lifecycle, internal audit, management review, and CAPA records.

0Ready
1Review
7Missing
2Samples
0Workbench
0Risks
0SoA
0Overdue
Nonconformity and CAPA

10.1 · ASM-1, B.12.6, B.21.4, IR-2, LOG-1

Review
not started0 workbench0 risks0 SoA0 overdue2 evidence2 samples3 gaps
Review and approvewei.tan@meridianpay.example
Internal Audit

9.2 · B.3.6, GOV-1, LOG-1

Missing
not started0 workbench0 risks0 SoA0 overdue0 evidence0 samples2 gaps
Collect recordoperating record
ISMS Scope and Boundaries

4.1, 4.2, 4.3 · ASM-1, B.3.6, B.8.3, GOV-1

Missing
not started0 workbench0 risks0 SoA0 overdue0 evidence0 samples2 gaps
Collect recordisms core
Management Review

9.3 · B.21.4, GOV-1, IR-2

Missing
not started0 workbench0 risks0 SoA0 overdue0 evidence0 samples2 gaps
Collect recordoperating record
Policy Lifecycle and Approval

5.2, 7.5, A.5.1 · B.3.6, GOV-1

Missing
not started0 workbench0 risks0 SoA0 overdue0 evidence0 samples2 gaps
Collect recordisms core
Risk Register

6.1.2 · ASM-1, B.3.6, GOV-1

Missing
not started0 workbench0 risks0 SoA0 overdue0 evidence0 samples2 gaps
Collect recordisms core

Object Model

B.1.3
Requirement

B.1.3 - Understanding the importance of cybersecurity

The organisation has established and implemented practices to develop the importance of cybersecurity within its business context and communicate this to all relevant stakeholders, such as employees, customers and partners.

promoterperformeradvocate
ClassicalCloudAI
AISuch practices include establishing mechanisms for: – The organisation to provide necessary security information about its AI systems to users and other relevant stakeholders, e.g., acceptable use policy of the AI systems in the organisation; and – Employees and external parties to report AI security concerns of the AI systems in the organisation.
CloudAs part of these practices, the organisation has established and implemented the cloud shared responsibility model with the CSP, e.g., through its commercial agreement with the CSP to establish clear roles and responsibilities between the organisation and the CSP.
Evidence Requirements
B.1.3.EV01

Approved governance, strategy, policy, or procedure document

manual_taskrow 7
B.1.3.EV02

Communication, review, and approval evidence from accountable leadership

manual_taskrow 7