What problem does it solve?
Compliance frameworks like NIST 800-53, ISO 27001, and SOC 2 were designed for pre-AI, network-centric threat models and lag years behind mid-2026 attack patterns. Organizations regularly pass audits for controls that are fully bypassed by current attacker TTPs, creating unaddressed risk masked as compliance.
Core Features & Use Cases
- Pre-Analyzed Gap Catalog: Built-in documentation of proven gaps for common controls (e.g., NIST 800-53 SI-2, ISO 27001 A.8.8) paired with real CVE evidence and MITRE ATLAS/ATT&CK TTP mappings.
- Structured Gap Declarations: Generates standardized, audit-ready gap declarations with RWEP-justified remediation requirements, global jurisdictional cross-walks, and D3FEND defensive technique mappings.
- Compliance Theater Detection: Includes a built-in test to identify when claimed compensating controls are effectively useless against current threats.
- Use Case: A security team evaluating NIST 800-53 AC-2 for AI agent access control can input the control ID and prompt injection threat scenario to get a documented gap showing the control is fully bypassed by AML.T0051, plus concrete remediation steps.
Quick Start
Use the framework-gap-analysis skill to produce a gap declaration for PCI DSS 4.0 Requirement 6.3.3 against AI-accelerated exploit weaponization.