Stop letting threat models die in a wiki: make STRIDE output double as compliance evidence
A threat model and a NIS2/DORA/ISO gap analysis describe the same system. Map each threat to the measure it satisfies, with article-level citations.
A threat model and a NIS2/DORA/ISO gap analysis describe the same system. Map each threat to the measure it satisfies, with article-level citations.
Provider, deployer, importer, distributor, GPAI provider — each EU AI Act role carries its own obligations. The role test, article references, and live dates.
RAG citations are decorative — no provenance contract links chunk to answer. Regulated work needs typed corpus tools, deterministic validation, and refusal.
6,041 Swedish statutes from Riksdagen, segmented to section level and served as an MCP — query by SFS number, chapter, and paragraf, every result cited.
DORA Article 28 sets the third-party obligations; the contract clauses live in Article 30. Each subsection mapped to ISO 27001 and SCF controls.
Every NIS2 Article 21(2) measure mapped to ISO 27001:2022 Annex A — and the three real gaps: reporting clock, management liability, supply chain depth.
Chat and RAG hallucinate regulatory citations. An MCP gateway adds routing, fan-out, tier auth, and deterministic citation validation — and when you need one.