[
  {
    "assuranceClaimIds": [
      "AC-K05-C01",
      "AC-K05-C10"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Governance",
    "id": "GOV-01",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls.",
        "framework": "NRC 10 CFR Part 73",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "73.54/73.55 or 73.100/73.110/73.120 as selected and applicable",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026"
      },
      {
        "applicability": "Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.",
        "framework": "NERC CIP",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "Current applicable CIP standards and implementation plans",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NERC-CIP-CATALOG-2026"
      }
    ],
    "name": "Authority and mission register",
    "objective": "Maintain signed, versioned authority, asset scope, allowed actions, prohibited outcomes, expiry, revocation, and review routes.",
    "researchCutoff": "2026-08-15",
    "slug": "authority-register"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C01",
      "AC-K05-C02"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Governance",
    "id": "GOV-02",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls.",
        "framework": "NRC 10 CFR Part 73",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "73.54/73.55 or 73.100/73.110/73.120 as selected and applicable",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026"
      },
      {
        "applicability": "Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.",
        "framework": "NERC CIP",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "Current applicable CIP standards and implementation plans",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NERC-CIP-CATALOG-2026"
      }
    ],
    "name": "Site-tailoring and applicability record",
    "objective": "Record the facility configuration, licensing path, BES status, contractual roles, jurisdictions, assumptions, exclusions, and evidence owner for every selected control.",
    "researchCutoff": "2026-08-15",
    "slug": "site-tailoring-record"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C02",
      "AC-K05-C09"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Governance",
    "id": "GOV-03",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls.",
        "framework": "NRC 10 CFR Part 73",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "73.54/73.55 or 73.100/73.110/73.120 as selected and applicable",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026"
      },
      {
        "applicability": "Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.",
        "framework": "NERC CIP",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "Current applicable CIP standards and implementation plans",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NERC-CIP-CATALOG-2026"
      }
    ],
    "name": "Hazard and assurance-defeater register",
    "objective": "Track hazards and evidence that can invalidate a claim, with owner, severity, disposition, expiry, and residual consequence.",
    "researchCutoff": "2026-08-15",
    "slug": "hazard-and-defeater-register"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C02"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Architecture",
    "id": "ARC-01",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls.",
        "framework": "NRC 10 CFR Part 73",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "73.54/73.55 or 73.100/73.110/73.120 as selected and applicable",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026"
      }
    ],
    "name": "Critical-function decomposition",
    "objective": "Decompose safety, security, power, cooling, compute, communications, evidence, and restoration into protected functions and dependencies.",
    "researchCutoff": "2026-08-15",
    "slug": "critical-function-decomposition"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C03"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Architecture",
    "id": "ARC-02",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls.",
        "framework": "NRC 10 CFR Part 73",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "73.54/73.55 or 73.100/73.110/73.120 as selected and applicable",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026"
      }
    ],
    "name": "Deterministic safety separation",
    "objective": "Use physical, one-way, or independently assured boundaries for safety-significant functions and validate every maintenance or support path.",
    "researchCutoff": "2026-08-15",
    "slug": "deterministic-safety-separation"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C03",
      "AC-K05-C04"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Architecture",
    "id": "ARC-03",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls.",
        "framework": "NRC 10 CFR Part 73",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "73.54/73.55 or 73.100/73.110/73.120 as selected and applicable",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026"
      }
    ],
    "name": "Trust-zone microsegmentation",
    "objective": "Enforce deny-by-default communications between workloads, management, OT, cooling, grid, and external services using authenticated identities and declared flows.",
    "researchCutoff": "2026-08-15",
    "slug": "trust-zone-microsegmentation"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C04"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Identity",
    "id": "ID-01",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      }
    ],
    "name": "Non-human workload identity",
    "objective": "Issue short-lived, cryptographically verifiable workload identities and remove shared machine credentials from control paths.",
    "researchCutoff": "2026-08-15",
    "slug": "nonhuman-workload-identity"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C01",
      "AC-K05-C04"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Identity",
    "id": "ID-02",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      }
    ],
    "name": "Privileged session control",
    "objective": "Broker, record, time-limit, and revoke privileged maintenance and emergency access; separate identity approval from technical reachability.",
    "researchCutoff": "2026-08-15",
    "slug": "privileged-session-control"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C04",
      "AC-K05-C09"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Supply Chain",
    "id": "SUP-01",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      }
    ],
    "name": "SBOM and component provenance",
    "objective": "Maintain machine-readable software, firmware, model, data, and hardware component inventories linked to exact releases and known defects.",
    "researchCutoff": "2026-08-15",
    "slug": "sbom-and-component-provenance"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C04",
      "AC-K05-C08"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Supply Chain",
    "id": "SUP-02",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      }
    ],
    "name": "Signed update and rollback",
    "objective": "Accept only authorized signed artifacts, test rollback, preserve prior known-good states, and prevent unreviewed downgrade or cross-environment promotion.",
    "researchCutoff": "2026-08-15",
    "slug": "signed-update-and-rollback"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C04"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Management Plane",
    "id": "MGT-01",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      }
    ],
    "name": "BMC isolation and attestation",
    "objective": "Place BMCs on a separately controlled management plane, deny ordinary egress, attest firmware, and isolate abnormal management behavior.",
    "researchCutoff": "2026-08-15",
    "slug": "bmc-isolation-and-attestation"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C04",
      "AC-K05-C09"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Management Plane",
    "id": "MGT-02",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      }
    ],
    "name": "Hardware-rooted attestation",
    "objective": "Verify boot, firmware, hypervisor, confidential-compute, and security-processor state before granting access to protected data or control functions.",
    "researchCutoff": "2026-08-15",
    "slug": "hardware-rooted-attestation"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C02",
      "AC-K05-C03"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "OT/Nuclear",
    "id": "OT-01",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls.",
        "framework": "NRC 10 CFR Part 73",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "73.54/73.55 or 73.100/73.110/73.120 as selected and applicable",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026"
      }
    ],
    "name": "Passive OT asset and dependency discovery",
    "objective": "Discover OT assets and communication dependencies without unsafe active probing, then reconcile against authorized configuration.",
    "researchCutoff": "2026-08-15",
    "slug": "passive-ot-asset-discovery"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C05",
      "AC-K05-C07"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "OT/Nuclear",
    "id": "OT-02",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls.",
        "framework": "NRC 10 CFR Part 73",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "73.54/73.55 or 73.100/73.110/73.120 as selected and applicable",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026"
      }
    ],
    "name": "Physics-informed detection",
    "objective": "Cross-check cyber telemetry against process invariants and independent measurements so statistically plausible but physically unsafe data is rejected.",
    "researchCutoff": "2026-08-15",
    "slug": "physics-informed-detection"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C03",
      "AC-K05-C07"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "OT/Nuclear",
    "id": "OT-03",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls.",
        "framework": "NRC 10 CFR Part 73",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "73.54/73.55 or 73.100/73.110/73.120 as selected and applicable",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026"
      }
    ],
    "name": "Independent safe-state path",
    "objective": "Provide an approved path to safe state that does not depend on the suspect enterprise network, model, identity provider, or timing source.",
    "researchCutoff": "2026-08-15",
    "slug": "independent-safe-state-path"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C07"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Power/Cooling",
    "id": "PWR-01",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls.",
        "framework": "NRC 10 CFR Part 73",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "73.54/73.55 or 73.100/73.110/73.120 as selected and applicable",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026"
      },
      {
        "applicability": "Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.",
        "framework": "NERC CIP",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "Current applicable CIP standards and implementation plans",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NERC-CIP-CATALOG-2026"
      }
    ],
    "name": "Load-rejection and islanding assurance",
    "objective": "Model and test credible load steps, islanding, resynchronization, black-start dependencies, and fail-safe load shedding.",
    "researchCutoff": "2026-08-15",
    "slug": "load-rejection-and-islanding-assurance"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C07"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Power/Cooling",
    "id": "CLG-01",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls.",
        "framework": "NRC 10 CFR Part 73",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "73.54/73.55 or 73.100/73.110/73.120 as selected and applicable",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026"
      },
      {
        "applicability": "Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.",
        "framework": "NERC CIP",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "Current applicable CIP standards and implementation plans",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NERC-CIP-CATALOG-2026"
      }
    ],
    "name": "Cooling independent protection",
    "objective": "Protect essential cooling with independent sensing, local control, safe fallback, and tested behavior under datacenter-management compromise.",
    "researchCutoff": "2026-08-15",
    "slug": "cooling-independent-protection"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C07"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Timing",
    "id": "TIM-01",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      }
    ],
    "name": "Assured time and holdover",
    "objective": "Use authenticated and diverse time sources, path-delay monitoring, holdover, clock-health evidence, and safe behavior when time confidence is lost.",
    "researchCutoff": "2026-08-15",
    "slug": "assured-time-and-holdover"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C05",
      "AC-K05-C10"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Autonomy",
    "id": "AUT-01",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "The directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems.",
        "framework": "DoD Directive 3000.09",
        "quality": "UNRESOLVED_APPLICABILITY",
        "reference": "Weapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behavior",
        "relationship": "APPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEM",
        "sourceId": "SRC-DODD-3000-09"
      }
    ],
    "name": "Bounded autonomous action tiering",
    "objective": "Separate observe, recommend, contain, protect, restore, and external-effect tiers; authorize tools and outcomes independently at each tier.",
    "researchCutoff": "2026-08-15",
    "slug": "bounded-action-tiering"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C05"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Autonomy",
    "id": "AUT-02",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      }
    ],
    "name": "Causal response guard",
    "objective": "Require an admissible causal path from observation to proposed action, reject actions with unknown physical effects, and record uncertainty.",
    "researchCutoff": "2026-08-15",
    "slug": "causal-response-guard"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C05"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Autonomy",
    "id": "AUT-03",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      }
    ],
    "name": "Multi-agent trust boundaries",
    "objective": "Authenticate agent-to-agent messages, isolate memory and tools, limit propagation depth, and treat peer output as untrusted evidence rather than authority.",
    "researchCutoff": "2026-08-15",
    "slug": "multi-agent-trust-boundaries"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C05",
      "AC-K05-C09"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Autonomy",
    "id": "AUT-04",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      }
    ],
    "name": "Model and data provenance and drift",
    "objective": "Version models, prompts, policies, training/evaluation data, retrieval corpora, thresholds, and drift observations; suspend affected actions when provenance fails.",
    "researchCutoff": "2026-08-15",
    "slug": "model-data-provenance-and-drift"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C06"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Physical Protection",
    "id": "PHY-01",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls.",
        "framework": "NRC 10 CFR Part 73",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "73.54/73.55 or 73.100/73.110/73.120 as selected and applicable",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026"
      },
      {
        "applicability": "The directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems.",
        "framework": "DoD Directive 3000.09",
        "quality": "UNRESOLVED_APPLICABILITY",
        "reference": "Weapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behavior",
        "relationship": "APPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEM",
        "sourceId": "SRC-DODD-3000-09"
      }
    ],
    "name": "Multi-sensor disagreement management",
    "objective": "Fuse independent modalities, expose confidence and disagreement, degrade suspect sensors, and prevent a single classifier from controlling high-consequence action.",
    "researchCutoff": "2026-08-15",
    "slug": "multi-sensor-disagreement-management"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C06"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Physical Protection",
    "id": "PHY-02",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls.",
        "framework": "NRC 10 CFR Part 73",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "73.54/73.55 or 73.100/73.110/73.120 as selected and applicable",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026"
      },
      {
        "applicability": "The directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems.",
        "framework": "DoD Directive 3000.09",
        "quality": "UNRESOLVED_APPLICABILITY",
        "reference": "Weapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behavior",
        "relationship": "APPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEM",
        "sourceId": "SRC-DODD-3000-09"
      }
    ],
    "name": "Non-destructive delay and access denial",
    "objective": "Use authorized access control, barriers, compartmentation, lockdown, tracking, alerting, and responder integration before considering any force-enabled capability.",
    "researchCutoff": "2026-08-15",
    "slug": "non-destructive-delay-and-access-denial"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C06"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Physical Protection",
    "id": "PHY-03",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls.",
        "framework": "NRC 10 CFR Part 73",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "73.54/73.55 or 73.100/73.110/73.120 as selected and applicable",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026"
      },
      {
        "applicability": "The directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems.",
        "framework": "DoD Directive 3000.09",
        "quality": "UNRESOLVED_APPLICABILITY",
        "reference": "Weapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behavior",
        "relationship": "APPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEM",
        "sourceId": "SRC-DODD-3000-09"
      }
    ],
    "name": "Counter-UAS authority separation",
    "objective": "Separate UAS detection and airspace restriction from interception, interference, seizure, disabling, or destruction; bind each action to actor-specific authority.",
    "researchCutoff": "2026-08-15",
    "slug": "counter-uas-authority-separation"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C06",
      "AC-K05-C07"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Physical Protection",
    "id": "EM-01",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls.",
        "framework": "NRC 10 CFR Part 73",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "73.54/73.55 or 73.100/73.110/73.120 as selected and applicable",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026"
      }
    ],
    "name": "Electromagnetic resilience",
    "objective": "Protect essential control, communications, timing, sensors, and restoration assets against credible conducted and radiated interference with tested degraded modes.",
    "researchCutoff": "2026-08-15",
    "slug": "electromagnetic-resilience"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C08"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Recovery",
    "id": "REC-01",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      }
    ],
    "name": "Clean-room restoration",
    "objective": "Maintain isolated recovery infrastructure, verified images, credential rotation, dependency order, evidence preservation, and post-restore attestation.",
    "researchCutoff": "2026-08-15",
    "slug": "clean-room-restoration"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C07",
      "AC-K05-C08"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Recovery",
    "id": "REC-02",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      }
    ],
    "name": "Critical-function recovery objectives",
    "objective": "Define and test function-specific safe-state, recovery-time, recovery-point, evidence, and service-priority objectives rather than a single enterprise metric.",
    "researchCutoff": "2026-08-15",
    "slug": "critical-function-rto-rpo"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C05",
      "AC-K05-C09",
      "AC-K05-C10"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Evidence",
    "id": "EVD-01",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.",
        "framework": "NERC CIP",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "Current applicable CIP standards and implementation plans",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NERC-CIP-CATALOG-2026"
      },
      {
        "applicability": "The directive expressly excludes autonomous cyberspace capabilities, unarmed platforms, and non-weapon autonomous systems.",
        "framework": "DoD Directive 3000.09",
        "quality": "UNRESOLVED_APPLICABILITY",
        "reference": "Weapon-system applicability, human judgment, V&V/T&E, robustness, transparency, and abort behavior",
        "relationship": "APPLIES ONLY IF CAPABILITY IS A COVERED WEAPON SYSTEM",
        "sourceId": "SRC-DODD-3000-09"
      }
    ],
    "name": "Tamper-evident decision receipts",
    "objective": "Record observation, evidence inputs, model and software versions, authority, proposed and executed action, outcome, rollback, and reviewer disposition.",
    "researchCutoff": "2026-08-15",
    "slug": "tamper-evident-decision-receipts"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C09"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Evidence",
    "id": "EVD-02",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.",
        "framework": "NERC CIP",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "Current applicable CIP standards and implementation plans",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NERC-CIP-CATALOG-2026"
      }
    ],
    "name": "Independent verification and replay",
    "objective": "Enable an independent party to reproduce the build, configuration, test result, decision logic, package, or recovery outcome within declared limits.",
    "researchCutoff": "2026-08-15",
    "slug": "independent-verification-and-replay"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C09"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Evidence",
    "id": "EVD-03",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.",
        "framework": "NERC CIP",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "Current applicable CIP standards and implementation plans",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NERC-CIP-CATALOG-2026"
      }
    ],
    "name": "Readiness downgrade on evidence failure",
    "objective": "Automatically mark readiness degraded, stale, unavailable, or suspended when required evidence expires, fails, contradicts the claim, or becomes inaccessible.",
    "researchCutoff": "2026-08-15",
    "slug": "readiness-downgrade-on-evidence-failure"
  },
  {
    "assuranceClaimIds": [
      "AC-K05-C01",
      "AC-K05-C10"
    ],
    "authorityBoundary": "Control design and mapping do not create mission authority, license approval, certification, or universal applicability.",
    "claimStatus": "PROJECT TECHNICAL PROPOSAL",
    "failureEvidence": [
      "missing or stale artifact",
      "control bypass",
      "unresolved defect",
      "scope mismatch",
      "unsupported compliance label",
      "unavailable operating evidence"
    ],
    "family": "Operations",
    "id": "OPS-01",
    "implementationEvidence": [
      "approved design and scope",
      "exact configuration or policy artifact",
      "test result",
      "defect and exception record",
      "operating observation where deployment is claimed",
      "last review and evidence owner"
    ],
    "lastReviewed": "2026-08-15",
    "mappings": [
      {
        "applicability": "Applies as guidance when OT is in scope; Revision 3 remains final while Revision 4 is under development.",
        "framework": "NIST SP 800-82 Rev. 3",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "OT security program, architecture, risk, and control guidance",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-82R3"
      },
      {
        "applicability": "Applies to identity- and resource-centric access design; does not replace OT safety analysis.",
        "framework": "NIST SP 800-207",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Zero Trust Architecture principles",
        "relationship": "INFORMS",
        "sourceId": "SRC-NIST-800-207"
      },
      {
        "applicability": "Useful for high-consequence pathway analysis; not a regulatory certification.",
        "framework": "INL Consequence-driven Cyber-informed Engineering",
        "quality": "INFORMATIVE_RELATIONSHIP",
        "reference": "Consequence prioritization and critical-function assurance",
        "relationship": "INFORMS",
        "sourceId": "SRC-INL-CCE"
      },
      {
        "applicability": "Only for an NRC-regulated facility within the selected licensing and security framework; license basis controls.",
        "framework": "NRC 10 CFR Part 73",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "73.54/73.55 or 73.100/73.110/73.120 as selected and applicable",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026"
      },
      {
        "applicability": "Only after BES registration, asset categorization, effective-date, and enforcement-jurisdiction analysis.",
        "framework": "NERC CIP",
        "quality": "PARTIAL_IMPLEMENTATION_SUPPORT",
        "reference": "Current applicable CIP standards and implementation plans",
        "relationship": "MAY IMPLEMENT OR SUPPORT",
        "sourceId": "SRC-NERC-CIP-CATALOG-2026"
      }
    ],
    "name": "Incident command and deconfliction",
    "objective": "Maintain clear cyber, physical, nuclear, grid, emergency, intelligence, law-enforcement, vendor, and executive roles with one current incident authority map.",
    "researchCutoff": "2026-08-15",
    "slug": "incident-command-and-deconfliction"
  }
]
