One engine. Any framework you can put in a catalog.
Aegis does not contain four hard-coded assessments. It contains one assessment engine and four catalogs of structured content. That distinction is the whole story of this page: frameworks are data, so the engine can adapt to almost any cybersecurity framework you need.
Frameworks are content, not code.
Frameworks are structured catalogs
Every framework in Aegis is a catalog of enumerated controls in a common three-level structure: functions, categories, and controls. Only the labels differ between regimes. The engine iterates whatever catalog it is given; it has no idea which acronym it is scoring, and it does not need one.
New frameworks arrive as content
Catalogs ship through the signed update pipeline: Ed25519-verified bundles, hash-checked files, atomic install, one-click rollback. Adding a framework is a data delivery, not a software release. Your deployment stays sealed and your code stays untouched.
Every catalog is versioned forever
Runs record the exact framework version they assessed. Update a catalog and history stays exactly as it was; scope profiles, crosswalks, and exports all carry the version with them. A framework can evolve without ever rewriting your past.
Four very different regimes, one engine.
The four catalogs in the box were chosen to prove generality: a certification standard, an attestation framework, a privacy regulation, and a voluntary framework. They differ in shape, language, and legal weight, and the engine treats them identically: 296 controls, enumerated completely, every run.
ISO/IEC 27001:2022
Certification standard93 Annex A controls across 4 themes. Certification scope profiles let the score match the engagement: the denominator is what you actually committed to.
SOC 2
Attestation framework61 criteria across all five Trust Services Categories, not just Security. Select the categories in scope and the rest leave the report entirely.
GDPR
Privacy regulation36 obligations across 4 areas, expressed as assessable controls. Proof that the engine handles law-shaped requirements, not only control-shaped ones.
NIST CSF 2.0
Voluntary framework106 subcategories across 6 functions, shipped as verbatim official text. The reference case for what a fully licensed catalog looks like in Aegis.
Catalog wording is disclosed honestly: NIST is verbatim, the other three are complete-coverage paraphrases with a verbatim overlay path for licensed deployers. Details on the Security & Trust page.
If it is a list of controls, Aegis can assess against it.
Sector regulations, national schemes, benchmark catalogs, or the internal control baseline your organization already runs on: if the framework can be expressed as a structured catalog of enumerable controls, the engine can scope it, score it, and audit-trail it like the four in the box.
Author
The framework is expressed as a structured catalog: every control enumerated, hierarchy mapped, wording sourced or paraphrased depending on licensing.
Validate
The catalog passes the same completeness checks as the shipped four: every control assessable, one result per control guaranteed, ids stable.
Deliver
The catalog ships to your deployment as a signed content bundle. From that moment it scopes, scores, crosswalks, and exports like any other framework.
Need a framework we have not shipped?
Custom framework onboarding is exactly the kind of work our design partner program exists for. Tell us which regime you need on the demo call, and we will tell you honestly what authoring it takes.
Frameworks that know about each other.
214 curated mappings connect related controls across the shipped frameworks, so an ISO gap can show you the SOC 2 coverage you already have, and a GDPR scope can seed an ISO one. Crosswalks are deliberately report-only: a mapping surfaces a connection and a human decides what it means. It never changes a verdict and never moves a score.
Which framework do you need?
Ask about it on the demo call and get a straight answer about what onboarding it takes.