Participant disclosure, and where this approach loses
This site is published by a project that sells the vault layer these instruments are delivered on. It also argues, at length, that nobody should trust a claim they cannot check. Both of those are true at once, so the interests are stated here rather than left to be inferred.
The disclosure
The check is available. The graph is JSON you can fetch, the positional hashes are recomputable with one shell command, the source documents are published raw, the site is a git repository with a public history, and the gaps are listed more prominently than the achievements.
And a harder version of the same problem
A participant cannot own the register.
This is the project's own conclusion about a related idea, and it applies here. A body that assesses conformity has to be independent of the thing being assessed; a body that publishes the instruments against which assessments are made is in a weaker but real version of the same position. Which is one more reason nothing here outputs a verdict — not out of caution, but because a verdict issued by a participant would be worth nothing even if it were correct.
The sales objection, named in advance
Where this approach loses
Six honest cases, because a page that only lists strengths is an advertisement.
| Situation | What loses, and to what |
|---|---|
| You need an answer this afternoon | A commercial compliance product will give you a structured answer today. This gives you one modelled instrument, a method, and a list of what is missing. If a deadline is the constraint, this loses. |
| You need coverage across many instruments | One instrument is modelled. Commercial mapping databases cover hundreds. Breadth is not the argument here and pretending otherwise would be the first dishonest sentence on the site. |
| You need ISO text | You will have to buy it. This site cannot give it to you, and a competitor who appears to is either licensed or is about to have a problem |
| Your auditor wants a percentage | There is not one, and there will not be. A finding that points at a provision is more defensible and less convenient |
| You want a maintained commercial product | This is a published method and one instrument, maintained by a small project. The amendment-detection pipeline that would keep it current does not exist — gap G7, and it is the gap that most undermines the value proposition |
| You are checking whether anyone did this first | They did. NIS2Onto, PrivComp-KG, the Maryland GDPR + PCI ontology, OSCAL and ClauseMatch are all named, with what each got right. A claim of being first would be false and would be caught |
AI co-authorship
The writing on this site was produced with AI assistance, attributed to Dinis Cruz with AI co-authorship, and the source documents carry the same attribution. That matters here more than it would elsewhere for one reason: this site's central argument is that a model asked to assess compliance will produce a plausible answer. The grounding ladder is the mechanism that makes that harder — and it applies to the pages as much as to the tools, which is why operative text is withheld pending re-derivation and why a disputed number is left off a page rather than resolved by guessing.
Licence and corrections
All content CC BY 4.0. Reuse it with attribution. If something here is wrong — a citation, a hash, a characterisation of a prior art project, a claim about what is shipped — the repository is public and a correction is a pull request. A site that asks to be checked has to make checking cheap.