[
  {
    "id": "OSR-K06-UK",
    "name": "United Kingdom",
    "qualification": "K06 point-in-time review of selected official United Kingdom, French, European Union, Australian, Republic of Korea, Canadian, United Nations, and ICRC sources completed on 2026-08-15. The review records publication status and bounded propositions only. It is not a legal opinion, facility applicability determination, operational authorization, or prediction of later currentness; no public runtime monitor and no live-host observation are claimed.",
    "reviewedAt": "2026-08-15T23:00:00Z",
    "slug": "united-kingdom",
    "sourceIds": [
      "SRC-UK-NCF-ABOUT-2026",
      "SRC-UK-GOV-CYBER-STRATEGY-2026"
    ],
    "status": "REVIEWED_POINT_IN_TIME",
    "supportedPropositions": [
      "The UK publicly describes NCF operations as accountable, precise, and calibrated.",
      "The UK strategy integrates resilience, national capability, disruption, and democratic oversight."
    ],
    "unavailableOrUnresolved": [
      "No source reviewed creates general private-sector offensive authority.",
      "Facility-specific authorization, targeting, and operation packages remain unavailable."
    ]
  },
  {
    "id": "OSR-K06-FR-EU",
    "name": "France and the European Union",
    "qualification": "K06 point-in-time review of selected official United Kingdom, French, European Union, Australian, Republic of Korea, Canadian, United Nations, and ICRC sources completed on 2026-08-15. The review records publication status and bounded propositions only. It is not a legal opinion, facility applicability determination, operational authorization, or prediction of later currentness; no public runtime monitor and no live-host observation are claimed.",
    "reviewedAt": "2026-08-15T23:00:00Z",
    "slug": "france-european-union",
    "sourceIds": [
      "SRC-FR-COMCYBER-LID-2026",
      "SRC-FR-COMCYBER-LIO-2026",
      "SRC-EU-NIS2-2022",
      "SRC-EU-CRA-IMPLEMENTATION-2026"
    ],
    "status": "REVIEWED_POINT_IN_TIME",
    "supportedPropositions": [
      "France publicly separates defensive and offensive military cyber mission sets.",
      "EU policy supports full-spectrum cyber defence, civilian-military coordination, private-sector cooperation, and advanced-AI cybersecurity action."
    ],
    "unavailableOrUnresolved": [
      "A military doctrine page is not authority for a private contractor.",
      "EU and French applicability to a named facility requires current legal and contractual analysis."
    ]
  },
  {
    "id": "OSR-K06-AU",
    "name": "Australia",
    "qualification": "K06 point-in-time review of selected official United Kingdom, French, European Union, Australian, Republic of Korea, Canadian, United Nations, and ICRC sources completed on 2026-08-15. The review records publication status and bounded propositions only. It is not a legal opinion, facility applicability determination, operational authorization, or prediction of later currentness; no public runtime monitor and no live-host observation are claimed.",
    "reviewedAt": "2026-08-15T23:00:00Z",
    "slug": "australia",
    "sourceIds": [
      "SRC-AU-ASD-OFFENSIVE-CYBER-2026",
      "SRC-AU-CYBER-STRATEGY-H2-2026"
    ],
    "status": "REVIEWED_POINT_IN_TIME",
    "supportedPropositions": [
      "Australia's strategy uses six cyber shields including critical infrastructure, sovereign capability, threat sharing, and resilience.",
      "Horizon 2 covers the 2026–2028 action period following completion of Horizon 1."
    ],
    "unavailableOrUnresolved": [
      "The strategy does not itself authorize a private entity to conduct extraterritorial cyber effects.",
      "Current sector obligations require separate legal review."
    ]
  },
  {
    "id": "OSR-K06-ROK",
    "name": "Republic of Korea",
    "qualification": "K06 point-in-time review of selected official United Kingdom, French, European Union, Australian, Republic of Korea, Canadian, United Nations, and ICRC sources completed on 2026-08-15. The review records publication status and bounded propositions only. It is not a legal opinion, facility applicability determination, operational authorization, or prediction of later currentness; no public runtime monitor and no live-host observation are claimed.",
    "reviewedAt": "2026-08-15T23:00:00Z",
    "slug": "republic-of-korea",
    "sourceIds": [
      "SRC-ROK-NIS-CYBER-PUBLICATIONS-2026",
      "SRC-ROK-MOFA-CYBER-LAW-POSITION-2025"
    ],
    "status": "REVIEWED_POINT_IN_TIME",
    "supportedPropositions": [
      "The 2024 strategy emphasizes proactive cyber defence, international cooperation, critical-infrastructure resilience, emerging technology, and integrated response.",
      "The official white paper documents the national framework and sector activity."
    ],
    "unavailableOrUnresolved": [
      "Exact English legal meaning must be verified against authoritative Korean text.",
      "No general private or facility-specific extraterritorial effects authority is established by these records."
    ]
  },
  {
    "id": "OSR-K06-CA",
    "name": "Canada",
    "qualification": "K06 point-in-time review of selected official United Kingdom, French, European Union, Australian, Republic of Korea, Canadian, United Nations, and ICRC sources completed on 2026-08-15. The review records publication status and bounded propositions only. It is not a legal opinion, facility applicability determination, operational authorization, or prediction of later currentness; no public runtime monitor and no live-host observation are claimed.",
    "reviewedAt": "2026-08-15T23:00:00Z",
    "slug": "canada",
    "sourceIds": [
      "SRC-CA-NATIONAL-CYBER-STRATEGY-2025"
    ],
    "status": "REVIEWED_POINT_IN_TIME",
    "supportedPropositions": [
      "Canada's 2025 strategy emphasizes whole-of-society engagement, agile leadership, protection partnerships, global leadership, and detecting and disrupting threat actors.",
      "The 2025–2026 threat assessment identifies ransomware and disruptive state activity as material risks."
    ],
    "unavailableOrUnresolved": [
      "A national strategy is not a delegation of offensive authority to private operators.",
      "The threat-assessment forecast is time-bounded and must be revalidated after 2026."
    ]
  },
  {
    "id": "OSR-K06-INTL",
    "name": "Selected international-law positions",
    "qualification": "K06 point-in-time review of selected official United Kingdom, French, European Union, Australian, Republic of Korea, Canadian, United Nations, and ICRC sources completed on 2026-08-15. The review records publication status and bounded propositions only. It is not a legal opinion, facility applicability determination, operational authorization, or prediction of later currentness; no public runtime monitor and no live-host observation are claimed.",
    "reviewedAt": "2026-08-15T23:00:00Z",
    "slug": "selected-international-law",
    "sourceIds": [
      "SRC-UN-ARSIWA-2001",
      "SRC-ICRC-CYBER-IHL-2026"
    ],
    "status": "REVIEWED_POINT_IN_TIME_WITH_DISPUTES",
    "supportedPropositions": [
      "Existing international law and the UN Charter apply to state conduct in cyberspace.",
      "IHL applies to and limits cyber operations during armed conflict, including protection of civilians and civilian infrastructure."
    ],
    "unavailableOrUnresolved": [
      "States do not uniformly agree on every sovereignty, due-diligence, countermeasure, imminence, or armed-attack threshold.",
      "The reviewed materials do not resolve a named operation's legality."
    ]
  },
  {
    "id": "OSR-K07-NRC",
    "name": "NRC advanced-reactor and cyber-security sources",
    "qualification": "Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.",
    "reviewedAt": "2026-08-15T23:30:00Z",
    "slug": "nrc-advanced-reactor-and-cybersecurity",
    "sourceIds": [
      "SRC-NRC-PART53-FINAL-2026",
      "SRC-NRC-RG571-R1-2023"
    ],
    "status": "REVIEWED_POINT_IN_TIME",
    "supportedPropositions": [
      "Part 53 is an official optional technology-inclusive framework for advanced-reactor licensing.",
      "RG 5.71 Revision 1 is official NRC cyber-security program guidance for nuclear power reactors."
    ],
    "unavailableOrUnresolved": [
      "No public source review decides applicability to a named datacenter or reactor.",
      "No source creates private operational or counter-UAS authority."
    ]
  },
  {
    "id": "OSR-K07-DOE",
    "name": "DOE Cyber-Informed Engineering",
    "qualification": "Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.",
    "reviewedAt": "2026-08-15T23:30:00Z",
    "slug": "doe-cyber-informed-engineering",
    "sourceIds": [
      "SRC-DOE-CIE-2026"
    ],
    "status": "REVIEWED_POINT_IN_TIME",
    "supportedPropositions": [
      "DOE describes CIE as integrating cybersecurity into engineering conception, design, development, and operation.",
      "The method emphasizes design and engineering controls against high-consequence cyber-enabled outcomes."
    ],
    "unavailableOrUnresolved": [
      "A CIE or CCE workshop is not a facility certification.",
      "Site findings require authorized facility evidence."
    ]
  },
  {
    "id": "OSR-K07-NIST-OT",
    "name": "NIST operational-technology security",
    "qualification": "Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.",
    "reviewedAt": "2026-08-15T23:30:00Z",
    "slug": "nist-operational-technology",
    "sourceIds": [
      "SRC-NIST-SP80082R3-2023",
      "SRC-NIST-SP80082R4-IPRD-2026"
    ],
    "status": "REVIEWED_POINT_IN_TIME",
    "supportedPropositions": [
      "SP 800-82 Revision 3 remains the final OT security publication at the K07 cutoff.",
      "NIST initiated a Revision 4 pre-draft process in January 2026."
    ],
    "unavailableOrUnresolved": [
      "The Revision 4 pre-draft notice is not a final control baseline.",
      "NIST guidance does not decide NRC, NERC, contract, or facility applicability by itself."
    ]
  },
  {
    "id": "OSR-K07-SCRM",
    "name": "NIST, NTIA, and CISA supply-chain assurance",
    "qualification": "Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.",
    "reviewedAt": "2026-08-15T23:30:00Z",
    "slug": "nist-and-cisa-supply-chain",
    "sourceIds": [
      "SRC-NIST-SP800161R1U1-2024",
      "SRC-NIST-SP1326-2026",
      "SRC-NTIA-SBOM-MINIMUM-2021",
      "SRC-CISA-HBOM-2023"
    ],
    "status": "REVIEWED_POINT_IN_TIME",
    "supportedPropositions": [
      "NIST publishes multilevel C-SCRM guidance and a final 2026 supplier due-diligence quick-start guide.",
      "NTIA and CISA publish software and hardware bill-of-materials transparency guidance."
    ],
    "unavailableOrUnresolved": [
      "Bills of materials do not prove absence of defects, compromise, counterfeit components, or installed-state equivalence.",
      "Contract-specific completeness and data rights remain unresolved until acquisition."
    ]
  },
  {
    "id": "OSR-K07-DIGITAL-TWIN-AI",
    "name": "Digital-twin and AI-system assurance",
    "qualification": "Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.",
    "reviewedAt": "2026-08-15T23:30:00Z",
    "slug": "digital-twin-and-ai-assurance",
    "sourceIds": [
      "SRC-NIST-IR8356-2025",
      "SRC-NIST-SP800218A-2024",
      "SRC-NIST-AIRMF-CI-CONCEPT-2026"
    ],
    "status": "REVIEWED_POINT_IN_TIME",
    "supportedPropositions": [
      "NIST IR 8356 addresses digital-twin cyber-security and trust considerations.",
      "SP 800-218A adds AI-model-specific secure development practices.",
      "NIST is developing a critical-infrastructure AI RMF profile."
    ],
    "unavailableOrUnresolved": [
      "The critical-infrastructure profile is not final at the cutoff.",
      "A digital twin is not presumed faithful to a site outside its validated range."
    ]
  },
  {
    "id": "OSR-K07-FAR",
    "name": "Federal performance and quality acquisition",
    "qualification": "Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.",
    "reviewedAt": "2026-08-15T23:30:00Z",
    "slug": "federal-performance-and-quality-acquisition",
    "sourceIds": [
      "SRC-FAR-37602-2026",
      "SRC-FAR-PART46-2026"
    ],
    "status": "REVIEWED_POINT_IN_TIME",
    "supportedPropositions": [
      "FAR 37.602 emphasizes required results and measurable performance standards in performance work statements.",
      "FAR Part 46 addresses inspection, quality control, evidence, nonconformance, and acceptance."
    ],
    "unavailableOrUnresolved": [
      "The public work packages are not solicitations or contract awards.",
      "Agency-specific clauses, security requirements, data rights and acquisition authority remain unresolved."
    ]
  }
]
